漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Download and export of file via default user role
Vulnerability Description
Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior to the attack. It is worth noting that the deterministic nature of the export name is lower risk as the UI for exporting would start the download at the same time, which once downloaded - deletes the export from the system. The endpoint for exporting should simply be patched to a higher privilege level.
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
AnythingLLM 访问控制错误漏洞
Vulnerability Description
AnythingLLM是符合业务要求的文档聊天机器人。 AnythingLLM存在访问控制错误漏洞。攻击者利用该漏洞可以获得对系统的访问权限,并导出数据库信息。
CVSS Information
N/A
Vulnerability Type
N/A