CVE-2024-4320 is a critical remote code execution (RCE) vulnerability affecting the parisneo/lollms-webui application. Specifically, the '/install_extension' endpoint improperly handles the 'name' parameter, leading to local file inclusion (LFI) and arbitrary code execution. This allows an unauthenticated attacker to execute arbitrary code on the server by crafting a malicious request. The vulnerability has a CVSS score of 9.8 (Critical), indicating a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Its high EPSS score and FAUCET Risk Score further emphasize the significant threat it poses. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, suggesting it is not yet under active exploitation. Community discussion and media coverage are minimal, which is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:lollms:lollms_web_ui:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.