Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f97w-xx7w-xwgf

Опубликовано: 06 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A JSON Injection vulnerability exists in the mintplex-labs/anything-llm application, specifically within the username parameter during the login process at the /api/request-token endpoint. The vulnerability arises from improper handling of values, allowing attackers to perform brute force attacks without prior knowledge of the username. Once the password is known, attackers can conduct blind attacks to ascertain the full username, significantly compromising system security.

A JSON Injection vulnerability exists in the mintplex-labs/anything-llm application, specifically within the username parameter during the login process at the /api/request-token endpoint. The vulnerability arises from improper handling of values, allowing attackers to perform brute force attacks without prior knowledge of the username. Once the password is known, attackers can conduct blind attacks to ascertain the full username, significantly compromising system security.

EPSS

Процентиль: 38%
0.0017
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-229
CWE-307

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values, allowing attackers to perform brute force attacks without prior knowledge of the username. Once the password is known, attackers can conduct blind attacks to ascertain the full username, significantly compromising system security.

EPSS

Процентиль: 38%
0.0017
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-229
CWE-307