CVE-2024-4328: CSRF in clear_personality_files_list in parisneo/lollms-webui

Published Jun 10, 2024
·
Updated

A Cross-Site Request Forgery (CSRF) vulnerability exists in the clearpersonalityfileslist function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing actions without their consent, such as deleting important files on the system. The issue is present in the application's handling of requests, making it susceptible to CSRF attacks that could lead to unauthorized actions being performed on behalf of the user.

Affected Software

1 affected component
parisneo Lollms Web Ui=9.6

Event History

Jun 10, 2024
CVE Published
via MITRE·07:27 AM
Data Sourced
via MITRE·07:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-4328?

CVE-2024-4328 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that could potentially lead to unauthorized actions being performed on behalf of authenticated users.

2

How do I fix CVE-2024-4328?

To fix CVE-2024-4328, implement proper CSRF protection mechanisms for the clear_personality_files_list function in the Lollms Webui.

3

Which version of Lollms Webui is affected by CVE-2024-4328?

CVE-2024-4328 affects Lollms Webui version 9.6.

4

What type of attack can exploit CVE-2024-4328?

CVE-2024-4328 can be exploited through a CSRF attack, allowing attackers to execute unauthorized commands on behalf of the user.

5

Is user authentication sufficient against CVE-2024-4328?

No, user authentication alone is not sufficient against CVE-2024-4328; CSRF tokens should also be employed to validate requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203