Vulnerability record · CVE-2024-1600 · published 10 April 2024
CVE-2024-1600: Lollms web ui php remote file inclusion vulnerability
Lollms · Lollms Web Ui
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (`../../`) followed by the desired system file path, URL encoded. Successful exploitation allows the attacker to read any file on the filesystem accessible by the web server. This issue arises due to improper control of filename for include/require statement in the application.
Description
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (`../../`) followed by the desired system file path, URL encoded. Successful exploitation allows the attacker to read any file on the filesystem accessible by the web server. This issue arises due to improper control of filename for include/require statement in the application.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/parisneo/lollms-webui/commit/49b0332e98d42dd5204dda53dee410b160106265 | Patch |
| https://huntr.com/bounties/29ec621a-bd69-4225-ab0f-5bb8a1d10c67 | ExploitThird Party Advisory |
| https://github.com/parisneo/lollms-webui/commit/49b0332e98d42dd5204dda53dee410b160106265 | Patch |
| https://huntr.com/bounties/29ec621a-bd69-4225-ab0f-5bb8a1d10c67 | ExploitThird Party Advisory |
Track CVE-2024-1600 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.