漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Input Validation in mintplex-labs/anything-llm
Vulnerability Description
In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is caught by a catch block, which in turn deletes all users and disables the 'multi_user_mode'. The vulnerability allows an attacker to remove all existing users and potentially create a new admin user without requiring a password, leading to unauthorized access and control over the application.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
AnythingLLM 输入验证错误漏洞
Vulnerability Description
AnythingLLM是符合业务要求的文档聊天机器人。 AnythingLLM 存在输入验证错误漏洞,该漏洞源于允许攻击者删除所有现有用户,并可能在不需要密码的情况下创建新的管理员用户,从而导致对应用程序进行未经授权的访问和控制。
CVSS Information
N/A
Vulnerability Type
N/A