CVE-2024-1522

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-1522
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1522.json
Published
2024-03-30T18:15:45Z
Modified
2024-04-02T21:15:34.205856Z
Details

The parisneo/lollms-webui does not have CSRF protections. As a result, an attacker is able to execute arbitrary OS commands via the /execute_code API endpoint by tricking a user into visiting a specially crafted webpage.

References

Affected packages

Git / github.com/parisneo/lollms-webui

Affected ranges

Type
GIT
Repo
https://github.com/parisneo/lollms-webui
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

v0.*

v0.0.1
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9

v3.*

v3.0
v3.5

v4.*

v4.0

v5.*

v5.0

v6.*

v6.0
v6.5
v6.5.0
v6.5rc2
v6.7

v7.*

v7.0

v8.*

v8.0
v8.5

v9.*

v9.0