Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44421 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic search Service (under construction), XTTS service, Petals service, vLLM service, and Motion Ctrl service, which lack CSRF protection. This vulnerability allows attackers to deceive users into unwittingly installing the XTTS service among other packages by submitting a malicious installation request. Successful exploitation results in attackers tricking users into performing actions without their consent. |
Mon, 07 Jul 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms
Lollms lollms-webui |
|
| CPEs | cpe:2.3:a:lollms:lollms-webui:9.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms
Lollms lollms-webui |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:55:10.037Z
Reserved: 2024-05-13T16:22:44.214Z
Link: CVE-2024-4839
Updated: 2024-08-01T20:55:10.037Z
Status : Analyzed
Published: 2024-06-24T13:15:11.900
Modified: 2025-07-07T17:31:29.717
Link: CVE-2024-4839
No data.
OpenCVE Enrichment
No data.
EUVD