Логотип exploitDog
bind:CVE-2024-11167
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-11167

Количество 2

Количество 2

nvd логотип

CVE-2024-11167

11 месяцев назад

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jw8w-84x3-c2r9

11 месяцев назад

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-11167

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-jw8w-84x3-c2r9

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.

CVSS3: 9.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу