parisneo/lollms-webui
cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*
- >v9.9, <= v9.9
A directory listing vulnerability has been identified in parisneo/lollms-webui versions v9.9 up to the latest release. This vulnerability allows an attacker to list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.
Exploitation of this vulnerability could lead to unauthorized directory listing, potentially exposing sensitive files or information on the affected Windows system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.