A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-03-30T18:02:59.260Z

Updated: 2024-08-01T18:40:21.324Z

Reserved: 2024-02-14T23:31:53.478Z

Link: CVE-2024-1522

cve-icon Vulnrichment

Updated: 2024-08-01T18:40:21.324Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-30T18:15:45.930

Modified: 2024-04-16T12:15:09.357

Link: CVE-2024-1522

cve-icon Redhat

No data.