PT-2024-35128 · Unknown · Anything-Llm
Published
2024-06-25
·
Updated
2025-07-15
·
CVE-2024-5216
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
anything-llm (affected versions not specified)
Description
A Denial of Service (DoS) condition can occur due to uncontrolled resource consumption. The issue arises from the application's failure to limit the size of
username fields, enabling attackers to create users with excessively bulky texts, resulting in the user management panel becoming unresponsive. This prevents administrators from performing critical user management actions and allows malicious users to perpetuate their presence within the system indefinitely, undermining the system's security posture and degrading overall system performance.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm