PT-2024-24862 · Unknown · Anything-Llm

Published

2024-08-09

·

Updated

2024-08-12

·

CVE-2024-3279

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions mintplex-labs/anything-llm (affected versions not specified)
Description The issue is related to improper access control in the import endpoint, allowing anonymous attackers to import their own database files. This can lead to the deletion or alteration of the existing anythingllm.db file, enabling attackers to serve malicious data or collect user information. The vulnerability arises from the application's failure to properly restrict access to data-import functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3279

Affected Products

Anything-Llm