Beveiligingsadvies

CVE-2024-8581

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-20 10:09:25
Laatst bijgewerkt 2025-10-15 12:50:41
Toegewezen door @huntr_ai
CVSS-score 9.1
Status PUBLISHED

Beschrijving

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.