CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.4. See the original NVD description below for full technical details.
CVE
CVE-2024-9919
Severity
HIGH
CVSS
8.4
EPSS
0.30%
Original NVD Description
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.
Related CVEs
Other vulnerabilities affecting the same vendor(s)