Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic search Service (under construction), XTTS service, Petals service, vLLM service, and Motion Ctrl service, which lack CSRF protection. This vulnerability allows attackers to deceive users into unwittingly installing the XTTS service among other packages by submitting a malicious installation request. Successful exploitation results in attackers tricking users into performing actions without their consent.

INFO

Published Date :

2024-06-24T12:47:59.441Z

Last Modified :

2024-08-01T20:55:10.037Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-4839 vulnerability.

Vendors Products
Lollms
  • Lollms-webui
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-4839.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact