Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-6250 PoC — LoLLMs 安全漏洞

Source
Associated Vulnerability
Title:LoLLMs 安全漏洞 (CVE-2024-6250)
Description:LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言多模式系统的 Web UI。 LoLLMs 9.6版本存在安全漏洞,该漏洞源于容易受到绝对路径遍历攻击,可以被利用来读取任何文件并在受影响的系统上列出任意目录。
Description
An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the open_file endpoint of lollms_advanced.py. The sanitize_path function with allow_absolute_path=True allows an attacker to access arbitrary files and directories on a Windows system. This vulnerability can be exploited to read any file and list arbitrary directories on the affected system.
File Snapshot

id: CVE-2024-6250 info: name: LOLLMS WebUI - Absolute Path Traversal author: ritikchaddha sev ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.