AnythingLLM是符合业务要求的文档聊天机器人。 AnythingLLM 存在路径遍历漏洞,该漏洞源于处理文件和文件夹删除请求时输入验证和规范化不足,允许具有默认角色帐户的未经授权的攻击者删除文件系统中的文件和文件夹,包括关键数据库文件,例如:anythingllm.db。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mintplex-labs | mintplex-labs/anything-llm | unspecified ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-0404 | Mass Assignment Vulnerability in mintplex-labs/anything-llm | |
| CVE-2024-3028 | Improper Input Validation in mintplex-labs/anything-llm | |
| CVE-2024-3029 | Improper Input Validation in mintplex-labs/anything-llm |
No comments yet