Логотип exploitDog
bind:CVE-2024-10366
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-10366

Количество 2

Количество 2

nvd логотип

CVE-2024-10366

11 месяцев назад

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h5p2-273c-rxjp

11 месяцев назад

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-10366

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-h5p2-273c-rxjp

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.

CVSS3: 7.6
0%
Низкий
11 месяцев назад

Уязвимостей на страницу