A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-03-30T18:02:59.260Z
Updated: 2024-08-01T18:40:21.324Z
Reserved: 2024-02-14T23:31:53.478Z
Link: CVE-2024-1522

Updated: 2024-08-01T18:40:21.324Z

Status : Awaiting Analysis
Published: 2024-03-30T18:15:45.930
Modified: 2024-11-21T08:50:45.060
Link: CVE-2024-1522

No data.