CVE-2024-7058: Relative Path Traversal in parisneo/lollms-webui
A vulnerability in the sanitizepath function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personalityfolder on the victim's computer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7058?
CVE-2024-7058 has been classified as a high-severity vulnerability due to its potential for unauthorized directory access.
How do I fix CVE-2024-7058?
To fix CVE-2024-7058, ensure that the path sanitization function correctly handles and rejects relative paths such as './'.
What software is affected by CVE-2024-7058?
CVE-2024-7058 affects the parusneo/lollms-webui software, specifically version 10 and later.
What type of attacks can CVE-2024-7058 enable?
CVE-2024-7058 can enable attackers to perform unauthorized access to sensitive directories on the victim's system.
Is CVE-2024-7058 being actively exploited in the wild?
As of now, there are no confirmed reports of CVE-2024-7058 being actively exploited, but it poses a serious risk if left unpatched.