CVE-2024-6971
CVSS 3.0 Score 3.4 of 10 (low)
Details
Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 22
Summary
CVE-2024-6971 is a newly disclosed path traversal vulnerability affecting the `lollms_file_system.py` file in the `parisneo/lollms-webui` repository. The `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` functions lack essential security measures like `sanitize_path_from_endpoint` and `sanitize_path`, enabling attackers to perform vectorize operations on `.sqlite` files placed in arbitrary directories. Potentially, an attacker can install multiple packages and trigger a system crash through this unsecured file manipulation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.