PT-2024-41083 · Qanything · Qanything

Published

2024-10-16

·

Updated

2025-08-01

·

CVE-2024-12866

CVSS v2.0
7.8
VectorAV:N/AC:L/Au:N/C:C/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

netease-youdao/qanything version v2.0.0

Description:

A local file inclusion vulnerability exists that allows an attacker to read arbitrary files on the file system. This can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files. The vulnerability is related to an incorrect restriction on the path name to the access-restricted directory.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-02215
CVE-2024-12866

Affected Products

Qanything