Описание
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an admin role and then be able to use this new account to have elevated privileges on the instance
Ссылки
- Patch
- ExploitThird Party Advisory
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.0 (исключая)
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.0041
Низкий
7.2 High
CVSS3
7.2 High
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 7.2
github
почти 2 года назад
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance
EPSS
Процентиль: 61%
0.0041
Низкий
7.2 High
CVSS3
7.2 High
CVSS3
Дефекты
CWE-284