PT-2024-37509 · Parisneo · Lollms

CVE-2024-6281

·

Published

2024-07-20

·

Updated

2026-07-07

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: parisneo/lollms versions prior to 9.5.1
Description: A path traversal issue exists in the apply settings function. The sanitize path function does not adequately secure the discussion db name parameter, allowing attackers to manipulate the path and potentially write to important system folders.
Recommendations: For versions prior to 9.5.1, update to version 9.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the apply settings function until a patch is available. Restrict access to the discussion db name parameter to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6281
GHSA-8MRM-R7H3-C3HJ
PYSEC-2026-1587

Affected Products

Lollms