CVE Vulnerabilities

CVE-2024-6281

Expected Behavior Violation

Published: Jul 20, 2024 | Modified: Jul 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A path traversal vulnerability exists in the apply_settings function of parisneo/lollms versions prior to 9.5.1. The sanitize_path function does not adequately secure the discussion_db_name parameter, allowing attackers to manipulate the path and potentially write to important system folders.

Weakness

A feature, API, or function does not perform according to its specification.

References