CVE-2024-6959

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/10/2024
Last modified:
03/11/2024

Description

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lollms:lollms_web_ui:9.8:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools