Loading HuntDB...

GHSA-mf32-4qcq-96wh

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing actions without their consent, such as deleting important files on the system. The issue is present in the application's handling of requests, making it susceptible to CSRF attacks that could lead to unauthorized actions being performed on behalf of the user.

Related CVEs

Key Information

GHSA ID
GHSA-mf32-4qcq-96wh
Published
June 10, 2024 9:31 AM
Last Modified
June 10, 2024 9:31 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.