A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-03-30T18:02:59.260Z
Updated: 2024-08-01T18:40:21.324Z
Reserved: 2024-02-14T23:31:53.478Z
Link: CVE-2024-1522
Vulnrichment
Updated: 2024-08-01T18:40:21.324Z
NVD
Status : Awaiting Analysis
Published: 2024-03-30T18:15:45.930
Modified: 2024-04-16T12:15:09.357
Link: CVE-2024-1522
Redhat
No data.