CVE-2024-9919 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninsta…
High CVSS: 8.4

CVE-2024-9919

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.
Vendor
Lollms
Product
Lollms Web Ui
CWE
CWE-306
Yayın Tarihi
2025-03-20 10:15:50
Güncelleme
2025-10-15 13:15:59
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar