Saifeddine ALOUI
27 exploits
Active since Mar 2024
lollms_web_ui < 9.5 - Path Traversal and Remote Code Execution via Config Parameter in Save Settings Endpoint
CVSS 8.4
Cross-site Scripting (XSS) in parisneo/lollms
CVSS 6.1
Stored XSS in parisneo/lollms
CVSS 9.6
Improper Access Control via Weak JWT Token in parisneo/lollms
CVSS 9.8
Unauthenticated File Upload in parisneo/lollms
CVSS 9.8
Server-Side Request Forgery (SSRF) in parisneo/lollms
CVSS 7.5
Insecure Direct Object Reference (IDOR) in parisneo/lollms
CVSS 8.3
lollms_web_ui 9.0-<9.2 - OS Command Injection via Discussion ID Parameter
CVSS 9.8
lollms_web_ui 9.0-<9.2 - Cross-Site Request Forgery via /execute_code Endpoint
CVSS 8.8
lollms-webui - Unauthenticated Denial of Service via /open_code_in_vs_code Endpoint
CVSS 7.5
lollms_web_ui 9.0-9.6 - Local File Inclusion via Personalities Route
CVSS 9.3
lollms-webui - SQL Injection via delete_discussion() Function
CVSS 9.8
lollms-webui < 9.3 - Unauthenticated Authentication Bypass via Host Parameter Check
CVSS 8.2
lollms_web_ui a9d16b0 - Path Traversal and Denial of Service via /select_database Endpoint
CVSS 9.1
lollms_web_ui < 9.3 - Cross-Site Request Forgery and Stored Cross-Site Scripting via Profile Picture Upload
CVSS 8.3
parisneo/lollms-webui < v9.5 - Unauthenticated Path Traversal and Remote Code Execution via reinstall_extension Endpoint
CVSS 9.6
lollms_web_ui < 9.5 - Path Traversal via User Infos Endpoint
CVSS 7.5
parisneo/lollms-webui - Path Traversal
CVSS 9.8
parisneo/lollms-webui - Command Injection
CVSS 8.4
Parisneo/lollms-webui <9.5 - Path Traversal
CVSS 9.8
lollms_web_ui < 9.5 - Remote Code Execution via Settings Bypass
CVSS 9.8
parisneo/lollms-webui <9.6 - XSS/Open Redirect
CVSS 7.3
lollms_web_ui < 10 - Cross-Site Request Forgery via install_comfyui Endpoint
CVSS 6.5
lollms_web_ui < 10 - Origin Validation Error via CORS Misconfiguration
CVSS 7.1
parisneo/lollms-webui V12 - Path Traversal
CVSS 9.1