CVE-2024-6674

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-29 13:15

Updated : 2024-11-01 20:34


NVD link : CVE-2024-6674

Mitre link : CVE-2024-6674

CVE.ORG link : CVE-2024-6674


JSON object : View

Products Affected

lollms

  • lollms_web_ui
CWE
CWE-346

Origin Validation Error