peter bassill · operator
$ cve CVE-2024-1520 JSON

CVE-2024-1520

9.8
CRITICAL · CVSS 3.0 · EPSS 48.2% (pctl 99)

Patch early

EPSS 48.2% — above the 10% action threshold.

Description

An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulnerability by injecting malicious OS commands, leading to unauthorized command execution on the underlying operating system. This could result in unauthorized access, data leakage, or complete system compromise.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS48.21% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2024-04-10
Last modified2026-06-17

Affected (1)

VendorProduct
lollmslollms web ui

References

→ the Explorer  ·  watch your stack  ·  NVD