Vulnerabilities > CVE-2024-0439 - Unspecified vulnerability in Mintplexlabs Anythingllm 0.0.1/0.1.0

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mintplexlabs

Summary

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.

Vulnerable Configurations

Part Description Count
Application
Mintplexlabs
3