CRITICAL🇵🇱 Wersja polska

CVE-2024-2362

CVSS 9.1v3.1pub. 2024-06-06upd. 2025-02-13

A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this vulnerability to delete any file on the system. The issue arises from the lack of adequate sanitization of user-supplied input in the 'del_preset' endpoint, where the application fails to prevent the use of absolute paths or directory traversal sequences ('..'). As a result, an attacker can send a specially crafted request to the 'del_preset' endpoint to delete files outside of the intended directory.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation and sanitization of file paths supplied by the user in the 'del_preset' endpoint. The application does not block the use of absolute paths or directory traversal sequences ('..'), which leads to inconsistencies in path handling between Windows and Linux environments. An attacker can send a specially crafted request to the 'del_preset' endpoint, specifying a path to a file located outside the intended directory, resulting in its deletion.

Impact

An unauthenticated attacker can delete any file accessible in the operating system, which may lead to permanent data loss, system destabilization, or complete system unavailability.

Mitigation & patch

Apply patches available from the vendor according to the references (https://huntr.com/bounties/2433d0a4-9ba0-474b-be1a-6fd5019770ba). It is recommended to update to the latest available version of the application and — as a temporary measure — restrict network access to the 'del_preset' endpoint using firewall or authorization mechanisms.

Who is affected

parisneo/lollms-webui version 9.3 running on the Windows platform

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Linux Kernel

    OS
    Linux
    all versions
  • Lollms Web Ui

    APP
    Lollms
    9.3
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit