A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.
CVE ID: CVE-2024-8581
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.1
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vendor: parisneo
Product: parisneo/lollms-webui
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 18.61% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)