{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-03T18:43:26.798","vulnerabilities":[{"cve":{"id":"CVE-2024-9597","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:49.320","lastModified":"2026-06-17T08:24:53.677","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit this by sending a specially crafted HTTP request to delete arbitrary directories."},{"lang":"es","value":"Existe una vulnerabilidad de Path Traversal en el endpoint `/wipe_database` de parisneo/lollms versión v12, que permite a un atacante eliminar cualquier directorio del sistema. Esta vulnerabilidad se debe a una validación incorrecta del parámetro `key`, que se utiliza para construir rutas de archivos. Un atacante puede explotarla enviando una solicitud HTTP especialmente manipulada para eliminar directorios arbitrarios."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"parisneo","product":"parisneo/lollms","versions":[{"version":"unspecified","lessThanOrEqual":"latest","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-20T17:50:41.171671Z","id":"CVE-2024-9597","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://huntr.com/bounties/1f6c8908-d486-4141-be55-25bd29933d8b","source":"security@huntr.dev"}]}}]}