CVE-2024-9919
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.
Vendor
Product
CWE
Yayın Tarihi
2025-03-20 10:15:50
Güncelleme
2025-10-15 13:15:59
Source Identifier
security@huntr.dev
KEV Date Added
-