PT-2024-15651 · Git+2 · Anything-Llm+1
Published
2024-02-27
·
Updated
2024-02-27
·
CVE-2024-0551
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Software (affected versions not specified)
Description
The issue allows exports of the database and associated exported information of the system via the default user role. An attacker would need to have been granted access to the system prior to the attack. The endpoint for exporting is at a lower privilege level than expected. The export process starts a download and then deletes the export from the system, which reduces the risk due to the deterministic nature of the export name.
Recommendations
To resolve the issue, the endpoint for exporting should be patched to a higher privilege level.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm
Mintplex-Labs/Anything-Llm