CVE-2024-8581
CVSS 3.0 Score 9.1 of 10 (critical)
Details
Summary
CVE-2024-8581 is a newly disclosed vulnerability affecting version V12 (Strawberry) of the `parisneo/lollms-webui` application. This issue resides in the `upload_app` function, which fails to filter user input on the `filename` value. As a result, an attacker can exploit this Path Traversal error to delete any file or directory on the targeted system. This vulnerability poses a significant risk, as it allows unauthorized modification or deletion of critical system files. System administrators are strongly advised to upgrade to a patched version of `parisneo/lollms-webui` to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.