Show filters
61 Total Results
Displaying 41-50 of 61
Sort by:
Attacker Value
Unknown

CVE-2024-1520

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulnerability by injecting malicious OS commands, leading to unauthorized command execution on the underlying operating system. This could result in unauthorized access, data leakage, or complete system compromise.
0
Attacker Value
Unknown

CVE-2024-1511

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to read, write, and in certain configurations execute arbitrary files on the server by exploiting various endpoints. The vulnerability can be exploited even when the service is bound to localhost, through cross-site requests facilitated by malicious HTML/JS pages.
0
Attacker Value
Unknown

CVE-2024-1522

Disclosure Date: March 30, 2024 (last updated April 16, 2024)
A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
0
Attacker Value
Unknown

CVE-2023-37523

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
Attacker Value
Unknown

CVE-2023-37522

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
Attacker Value
Unknown

CVE-2023-37521

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.
Attacker Value
Unknown

CVE-2023-46315

Disclosure Date: October 22, 2023 (last updated October 31, 2023)
The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated by reading /proc/self/environ to discover credentials.
Attacker Value
Unknown

CVE-2023-39141

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
Attacker Value
Unknown

CVE-2023-28023

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
Attacker Value
Unknown

CVE-2023-28021

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
The BigFix WebUI uses weak cipher suites.