Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-4841 PoC — LoLLMs 安全漏洞

Source
Associated Vulnerability
Title:LoLLMs 安全漏洞 (CVE-2024-4841)
Description:LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言多模式系统的 Web UI。 LoLLMs 存在安全漏洞,该漏洞源于缺乏输入清理,存在路径遍历漏洞,攻击者可以预测受害者计算机上的文件夹、子文件夹和文件。
Description
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest.
File Snapshot

id: CVE-2024-4841 info: name: LoLLMS WebUI - Subfolder Prediction via Path Traversal author: s4 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.