CVE-2024-9919
CVSS 3.0 Score 8.4 of 10 (high)
Details
Summary
CVE-2024-9919 is a newly disclosed vulnerability affecting the parisneo/lollms-webui V13 application. The issue lies in the uninstall endpoint, which lacks an essential authentication check. As a result, attackers can exploit this weakness to delete directories unauthorizedly through the /uninstall/{app_name} API endpoint. The check_access() function, responsible for verifying client_s IDs, is bypassed in this process, enabling unauthenticated directory deletions. This vulnerability poses a significant risk to the security of systems utilizing the affected software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.