Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9597


A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit this by sending a specially crafted HTTP request to delete arbitrary directories.


Published

2025-03-20T10:15:49.320

Last Modified

2025-03-20T10:15:49.320

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.0: 7.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products

-


References