CVE-2024-10047: Directory Listing Vulnerability in parisneo/lollms-webui
parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /openfile endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10047?
CVE-2024-10047 is categorized as a high severity vulnerability due to its ability to expose sensitive directory information on Windows systems.
How do I fix CVE-2024-10047?
To fix CVE-2024-10047, you should upgrade to a version of parisneo/lollms-webui that is newer than v9.9 and ensures proper input validation.
What type of vulnerability is CVE-2024-10047?
CVE-2024-10047 is a directory listing vulnerability that allows unauthorized access to arbitrary directories.
Who is affected by CVE-2024-10047?
Users of parisneo/lollms-webui versions v9.9 to the latest are affected by CVE-2024-10047.
Can CVE-2024-10047 be exploited remotely?
Yes, CVE-2024-10047 can be exploited remotely by an attacker sending crafted HTTP requests to the /open_file endpoint.