Vulnerability Database

296,489

Total vulnerabilities in the database

CVE-2024-5824

A path traversal vulnerability in the /set_personality_config endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the configs/config.yaml file. This can lead to remote code execution by changing server configuration properties such as force_accept_remote_access and turn_on_code_validation.

CVSS v3:

  • Severity: Unknown
  • Score:
  • AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H