8.1
CWE
352
EPSS
0.048%
Advisory Published
Updated

CVE-2024-4328: CSRF in clear_personality_files_list in parisneo/lollms-webui

First published: Mon Jun 10 2024(Updated: )

A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing actions without their consent, such as deleting important files on the system. The issue is present in the application's handling of requests, making it susceptible to CSRF attacks that could lead to unauthorized actions being performed on behalf of the user.

Credit: security@huntr.dev

Affected SoftwareAffected VersionHow to fix
Lollms Web UI=9.6

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-4328?

    CVE-2024-4328 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that could potentially lead to unauthorized actions being performed on behalf of authenticated users.

  • How do I fix CVE-2024-4328?

    To fix CVE-2024-4328, implement proper CSRF protection mechanisms for the clear_personality_files_list function in the Lollms Webui.

  • Which version of Lollms Webui is affected by CVE-2024-4328?

    CVE-2024-4328 affects Lollms Webui version 9.6.

  • What type of attack can exploit CVE-2024-4328?

    CVE-2024-4328 can be exploited through a CSRF attack, allowing attackers to execute unauthorized commands on behalf of the user.

  • Is user authentication sufficient against CVE-2024-4328?

    No, user authentication alone is not sufficient against CVE-2024-4328; CSRF tokens should also be employed to validate requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203