Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0798

Опубликовано: 26 фев. 2024
Источник: nvd
CVSS3: 8.1
CVSS3: 6.5
EPSS Низкий

Описание

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mintplexlabs:anythingllm:-:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00166
Низкий

8.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-272
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.1
github
почти 2 года назад

A user with a `default` role given to them by the admin can sent `DELETE` HTTP requests to `remove-folder` and `remove-document` to delete folders and source files from the instance even when their role should explicitly not allow this action on the system.

EPSS

Процентиль: 38%
0.00166
Низкий

8.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-272
NVD-CWE-noinfo