CVE-2024-11302
CVSS 3.0 Score 8 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 304
Summary
CVE-2024-11302 is a vulnerability affecting version V14 of the parisneo/lollms repository. The issue lies in the lack of a check_access() function in the lollms_binding_infos module, leading to unauthorized access and manipulation. Attackers can add, modify, or remove bindings arbitrarily, impacting the /install_binding and /reinstall_binding endpoints, among others. This vulnerability enables unauthorized access and manipulation of binding settings without the need for the client_id value.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.