Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0765

Опубликовано: 03 мар. 2024
Источник: nvd
CVSS3: 9.6
CVSS3: 6.5
EPSS Низкий

Описание

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the /export-data endpoint of the system and then unzip and read that export that would enable you do exfiltrate data of the system at that save state.

This would require the attacked to be granted explicit access to the system, but they can do this at any role. Additionally, post-download, the data is deleted so no evidence would exist that the exfiltration occured.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Версия до 1.0.0 (исключая)

EPSS

Процентиль: 22%
0.00072
Низкий

9.6 Critical

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.6
github
почти 2 года назад

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and read that export that would enable you do exfiltrate data of the system at that save state. This would require the attacked to be granted explicit access to the system, but they can do this at any role. Additionally, post-download, the data is deleted so no evidence would exist that the exfiltration occured.

EPSS

Процентиль: 22%
0.00072
Низкий

9.6 Critical

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200