Beveiligingsadvies

CVE-2024-7058

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-20 10:09:45
Laatst bijgewerkt 2025-03-20 18:35:07
Toegewezen door @huntr_ai
CVSS-score 4.4
Status PUBLISHED

Beschrijving

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on the victim's computer.