U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-6959

Change History

New CVE Received from huntr.dev 10/13/2024 9:15:10 AM

Action Type Old Value New Value
Added Description

								
							
							
						
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.
Added CVSS V3

								
							
							
						
huntr.dev AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Added CWE

								
							
							
						
huntr.dev CWE-400
Added Reference

								
							
							
						
huntr.dev https://huntr.com/bounties/6394d32e-f35c-418a-95b8-e7254ed0bc8e [No types assigned]