AnythingLLM是Mintplex开源的一个一体化AI应用程序。 AnythingLLM 1.3.1版本存在安全漏洞,该漏洞源于具有Default权限的用户可以通过更改用户cookie中的id参数访问其他用户的个人资料图片。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mintplex-labs | mintplex-labs/anything-llm | unspecified ~ 1.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6842 | Exposure of Sensitive Information in mintplex-labs/anything-llm | |
| CVE-2024-7771 | Denial of Service in mintplex-labs/anything-llm | |
| CVE-2024-8196 | Missing Authentication for Critical Function in mintplex-labs/anything-llm | |
| CVE-2024-8248 | Path Traversal in mintplex-labs/anything-llm | |
| CVE-2024-8251 | Prisma Injection in mintplex-labs/anything-llm | |
| CVE-2024-8249 | Unauthenticated Denial of Service (DoS) in mintplex-labs/anything-llm | |
| CVE-2024-10109 | Incorrect Authorization in mintplex-labs/anything-llm | |
| CVE-2024-10513 | Path Traversal in mintplex-labs/anything-llm |
No comments yet