CVE-2024-6959
Lollms
CVE-2024-6959 is a Denial of Service vulnerability in parisneo/lollms-webui version 9.8, triggered by uploading a malicious audio file. The vulnerability allows an attacker to cause service disruption and resource exhaustion. By appending excessive characters to a multipart boundary, an attacker can force the system to continuously process data, leading to inaccessibility. The absence of CSRF protection further enables remote exploitation. Although the CVSS score is 7.1, the SOCRadar Vulnerability Risk Score (SVRS) is 65, indicating a moderate risk that warrants monitoring. This vulnerability can lead to significant downtime and negatively impact user experience. Organizations using lollms-webui should apply necessary patches or mitigations immediately to prevent potential attacks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.