NetEase QAnything是中国NetEase公司的一个支持任意文件格式的本地知识库问答系统。 NetEase QAnything 2.0.0及之前版本存在授权问题漏洞,该漏洞源于/api/local_doc_qa/get_file_base64和/api/local_doc_qa/get_doc端点存在身份验证绕过,可能导致未经身份验证的攻击者访问任意上传的文件或文档,枚举文件标识符并检索base64编码文件或解析的文档片段,无需所有权验证即可泄露跨租户知识库内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| netease-youdao | QAnything | ≤ 2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netease-youdao | QAnything | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet