CVE-2024-4841: LoLLMS WebUI – Subfolder Prediction via Path Traversal

CVE-2024-4841: LoLLMS WebUI - Subfolder Prediction via Path Traversal-渗透云记 - 专注于网络安全与技术分享
CVE-2024-4841: LoLLMS WebUI – Subfolder Prediction via Path Traversal
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-4841: LoLLMS WebUI – Subfolder Prediction via Path Traversal

漏洞描述

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享