A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this vulnerability to delete any file on the system. The issue arises from the lack of adequate sanitization of user-supplied input in the 'del_preset' endpoint, where the application fails to prevent the use of absolute paths or directory traversal sequences ('..'). As a result, an attacker can send a specially crafted request to the 'del_preset' endpoint to delete files outside of the intended directory.
The vulnerability results from insufficient validation and sanitization of file paths supplied by the user in the 'del_preset' endpoint. The application does not block the use of absolute paths or directory traversal sequences ('..'), which leads to inconsistencies in path handling between Windows and Linux environments. An attacker can send a specially crafted request to the 'del_preset' endpoint, specifying a path to a file located outside the intended directory, resulting in its deletion.
An unauthenticated attacker can delete any file accessible in the operating system, which may lead to permanent data loss, system destabilization, or complete system unavailability.
Apply patches available from the vendor according to the references (https://huntr.com/bounties/2433d0a4-9ba0-474b-be1a-6fd5019770ba). It is recommended to update to the latest available version of the application and — as a temporary measure — restrict network access to the 'del_preset' endpoint using firewall or authorization mechanisms.
parisneo/lollms-webui version 9.3 running on the Windows platform
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HLinux Kernel
OSLinuxall versionsLollms Web Ui
APPLollms9.3Microsoft Windows
OSMicrosoftall versions
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit