Beveiligingsadvies

CVE-2024-9919

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-20 10:09:56
Laatst bijgewerkt 2025-10-15 12:50:47
Toegewezen door @huntr_ai
CVSS-score 8.4
Status PUBLISHED

Beschrijving

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.