Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h35f-g2pq-8xq7

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.

EPSS

Процентиль: 17%
0.00053
Низкий

7.5 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.

EPSS

Процентиль: 17%
0.00053
Низкий

7.5 High

CVSS3

Дефекты

CWE-346