CVE-2024-8024

Publication date

2025-03-20 10:10:09

Family

@huntr_ai

State

PUBLISHED

Description

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.