First published: Tue Oct 29 2024(Updated: )
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Parisneo Lollms | <10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6674 is considered a critical security vulnerability due to its potential for sensitive information theft and unauthorized actions.
To resolve CVE-2024-6674, update lollms-webui to version 10 or later to address the CORS misconfiguration.
CVE-2024-6674 allows attackers to steal sensitive information such as logs, browser sessions, and private API keys.
Any users of lollms-webui versions prior to 10 are affected by CVE-2024-6674.
Exploiting CVE-2024-6674 can enable attackers to perform actions on behalf of the user and compromise sensitive data.