← Back

CVE-2024-1646

nvd nist
Published: Apr 16, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Exploitability: 3.9 / Impact: 4.2
Source: security@huntr.dev (Secondary)

Description

parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict access, which is inadequate when the application is bound to a specific interface, allowing unauthorized access to endpoints such as '/restart_program', '/update_software', '/check_update', '/start_recording', and '/stop_recording'. This vulnerability can lead to denial of service, unauthorized disabling or overriding of recordings, and potentially other impacts if certain features are enabled in the configuration.

Affected (1)

Products: Lollms: Lollms Webui
1 product
Lollms Webui
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 9.3

References (4)

Source: security@huntr.dev
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.