CVE-2024-6985
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2024-6985 is a newly identified path traversal vulnerability affecting the api open_personality_folder endpoint in the lollms-webui application developed by parisneo. The issue stems from the improper sanitization of the personality_folder parameter, enabling attackers to traverse directories and access arbitrary files within the victim's personality_folder, despite the sanitize_path setting. This vulnerability could potentially lead to unauthorized data disclosure or privilege escalation. Users are strongly advised to apply patches or updates as soon as they become available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.