A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their knowledge, by sending specially crafted CSRF forms. This issue affects the installation process, including the installation of Binding zoo and Models zoo, by unexpectedly resetting programs. The vulnerability is due to the lack of CSRF protection in the affected function.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44033 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their knowledge, by sending specially crafted CSRF forms. This issue affects the installation process, including the installation of Binding zoo and Models zoo, by unexpectedly resetting programs. The vulnerability is due to the lack of CSRF protection in the affected function. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 Aug 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms
Lollms lollms-webui |
|
| CPEs | cpe:2.3:a:lollms:lollms-webui:9.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms
Lollms lollms-webui |
Thu, 03 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:parisneo:lollms-webui:9.6:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:40:47.179Z
Reserved: 2024-05-01T21:34:39.918Z
Link: CVE-2024-4403
Updated: 2024-06-12T14:19:07.926Z
Status : Analyzed
Published: 2024-06-10T15:15:52.703
Modified: 2025-08-15T20:39:51.013
Link: CVE-2024-4403
No data.
OpenCVE Enrichment
No data.
EUVD