
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-4315 affects parisneo/lollms version 9.5, which contains a Local File Inclusion (LFI) vulnerability due to insufficient path sanitization. The vulnerability was discovered in the sanitize_path_from_endpoint function, which fails to properly handle Windows-style paths using backward slashes (NVD).
The vulnerability stems from improper sanitization of Windows-style paths (backward slash \) in the sanitize_path_from_endpoint function. The security flaw allows attackers to perform directory traversal attacks specifically on Windows systems. The vulnerability has been assigned a CVSS v3.0 base score of 9.1 (CRITICAL) with the vector string CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H, indicating high severity with network accessibility and no required privileges (NVD).
The vulnerability enables attackers to read or delete any file on the Windows filesystem through various routes, including personalities and /del_preset endpoints. This can lead to unauthorized access to sensitive files and potential system compromise, affecting the system's availability (NVD).
The vulnerability can be exploited through various routes in the application, specifically targeting the personalities and /del_preset endpoints. The attack requires no special privileges or user interaction, making it highly exploitable (NVD).
A fix has been implemented in a security update, as evidenced by the commit 95ad36eeffc6a6be3e3f35ed35a384d768f0ecf6. The patch improves path sanitization by properly handling Windows-style paths and implementing stricter security checks (Github Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."