PT-2024-23313 · Mintplex · Anything-Llm
Published
2024-04-15
·
Updated
2025-07-09
·
CVE-2024-3028
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mintplex-labs/anything-llm (affected versions not specified)
Description
The issue is due to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the
logo filename parameter in the "system-preferences" API endpoint, an attacker can construct requests to read sensitive files or the application's '.env' file, and even delete files by setting the logo filename to the path of the target file and invoking the "remove-logo" API endpoint. This is a result of the lack of proper sanitization of user-supplied input.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm