296,489
Total vulnerabilities in the database
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.
Software | From | Fixed in |
---|---|---|
lollms / lollms_web_ui | 13 | 13.x |