CVE-2024-2356 | parisneo lollms-webui up to 9.4 /reinstall_extension ExtensionBuilder.build_extension data.name path traversal (EUVD-2024-27309)
A vulnerability classified as critical was found in parisneo lollms-webui up to 9.4. This affects the function ExtensionBuilder.build_extension of the file /reinstall_extension. Executing a manipulation of the argument data.name can lead to path traversal: '\..\filename'.
The identification of this vulnerability is CVE-2024-2356. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.