Critical severity9.3NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026
CVE-2024-1600
CVE-2024-1600
Description
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the /personalities route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (../../) followed by the desired system file path, URL encoded. Successful exploitation allows the attacker to read any file on the filesystem accessible by the web server. This issue arises due to improper control of filename for include/require statement in the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/parisneo/lollms-webui/commit/49b0332e98d42dd5204dda53dee410b160106265nvdPatch
- huntr.com/bounties/29ec621a-bd69-4225-ab0f-5bb8a1d10c67nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.