parisneo/lollms-webui
0 remedies
cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*
0 remedies
- 13
A vulnerability exists in parisneo/lollms-webui version 13, where the uninstall endpoint lacks proper authentication checks. The /uninstall/{app_name} API endpoint fails to verify the client_id, allowing attackers to delete directories without authorization.
Exploitation of this vulnerability allows for unauthorized directory deletions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.