Description

A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as `force_accept_remote_access` and `turn_on_code_validation`.

INFO

Published Date :

2024-06-27T18:45:26.668Z

Last Modified :

2024-08-01T21:25:03.266Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-5824 vulnerability.

Vendors Products
Parisneo
  • Lollms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-5824.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact