Vulnerabilities > CVE-2024-0795 - Unspecified vulnerability in Mintplexlabs Anythingllm 0.0.1/0.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- https://github.com/mintplex-labs/anything-llm/commit/9a237db3d1f66cdbcf5079599258f5fb251c5564
- https://github.com/mintplex-labs/anything-llm/commit/9a237db3d1f66cdbcf5079599258f5fb251c5564
- https://huntr.com/bounties/f69e3307-7b44-4776-ac60-2990990723ec
- https://huntr.com/bounties/f69e3307-7b44-4776-ac60-2990990723ec