{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T03:33:58.609","vulnerabilities":[{"cve":{"id":"CVE-2024-11302","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:25.003","lastModified":"2026-06-17T06:57:29.737","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and manipulation of binding settings without requiring the client_id value."},{"lang":"es","value":"La falta de la función check_access() en el módulo lollms_binding_infos del repositorio parisneo/lollms (versión V14) permite a los atacantes añadir, modificar y eliminar enlaces arbitrariamente. Esta vulnerabilidad afecta a los endpoints /install_binding y /reinstall_binding, entre otros, lo que permite el acceso no autorizado y la manipulación de la configuración de enlaces sin necesidad del valor client_id."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"parisneo","product":"parisneo/lollms","versions":[{"version":"unspecified","lessThanOrEqual":"latest","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-20T17:52:06.533902Z","id":"CVE-2024-11302","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-304"}]}],"references":[{"url":"https://huntr.com/bounties/e341304b-4651-4de9-b7b9-b89aead3b46e","source":"security@huntr.dev"}]}}]}