Beveiligingsadvies

CVE-2024-4287

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-05-20 12:24:51
Laatst bijgewerkt 2024-08-01 20:33:53
Toegewezen door @huntr_ai
CVSS-score 8.1
Status PUBLISHED

Beschrijving

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slug/update`, allowing it to be executed as part of a database query without restrictions. This flaw enables users with a manager role to craft a request that includes nested write operations, effectively allowing them to create new Administrator accounts.