Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage, which can then trigger arbitrary LoLLMS-XTTS API requests. This issue can lead to the reading and writing of audio files and, when combined with other vulnerabilities, could allow for the reading of arbitrary files on the system and writing files outside the permitted audio file location.

INFO

Published Date :

2024-06-24T03:06:46.088Z

Last Modified :

2024-08-01T20:40:47.283Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-4499 vulnerability.

Vendors Products
Lollms
  • Lollms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-4499.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact