漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Path Traversal in mintplex-labs/anything-llm
Vulnerability Description
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anythingllm.db' database file. By exploiting the vulnerable endpoint '/api/document/move-files', an attacker can move the database file to a publicly accessible directory, download it, and subsequently delete it. This can lead to unauthorized access to sensitive data, privilege escalation, and potential data loss.
CVSS Information
N/A
Vulnerability Type
相对路径遍历
Vulnerability Title
AnythingLLM 安全漏洞
Vulnerability Description
AnythingLLM是Mintplex开源的一个一体化AI应用程序。 AnythingLLM 1.2.2之前版本存在安全漏洞,该漏洞源于路径遍历漏洞,可能导致未经授权的数据库文件访问和删除。
CVSS Information
N/A
Vulnerability Type
N/A