CVE-2024-2366 — Command Injection in WEB UI
Severity
9.0CRITICALNVD
EPSS
2.3%
top 15.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16
Description
A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due to insufficient path sanitization, allowing an attacker to exploit path traversal to navigate to arbitrary directories. By manipulating the binding_path to point to a controlled directory and uploading a malicious __init__.py file, an attacke…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0
Affected Packages2 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-jgmp-p428-99m5: A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in loll↗2024-05-16