A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-23T14:33:33.798Z
Updated: 2024-08-01T20:55:10.099Z
Reserved: 2024-05-13T16:43:36.597Z
Link: CVE-2024-4841
Vulnrichment
Updated: 2024-08-01T20:55:10.099Z
NVD
Status : Awaiting Analysis
Published: 2024-06-23T15:15:09.233
Modified: 2024-06-24T12:57:36.513
Link: CVE-2024-4841
Redhat
No data.