Vulnerabilities > CVE-2024-0795 - Unspecified vulnerability in Mintplexlabs Anythingllm 0.0.1/0.1.0

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mintplexlabs

Summary

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance

Vulnerable Configurations

Part Description Count
Application
Mintplexlabs
3