漏洞标题
mintplex-labs/anything-llm中的大规模赋值漏洞
漏洞描述信息
mintplex-labs/anything-llm仓库中的`/api/invite/:code`端点存在大规模分配漏洞,允许未授权创建高权限账户。攻击者可以通过拦截和修改邀请链接创建账户过程中的HTTP请求,添加一个带有`admin`值的`role`属性,从而获得管理员访问权限。这个问题是由于缺乏属性白名单和黑名单,使得攻击者能够利用系统并以管理员身份执行操作。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
特权管理不恰当
漏洞标题
Mass Assignment Vulnerability in mintplex-labs/anything-llm
漏洞描述信息
A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts. By intercepting and modifying the HTTP request during the account creation process via an invitation link, an attacker can add a `role` property with `admin` value, thereby gaining administrative access. This issue arises due to the lack of property allowlisting and blocklisting, enabling the attacker to exploit the system and perform actions as an administrator.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
AnythingLLM 安全漏洞
漏洞描述信息
AnythingLLM是符合业务要求的文档聊天机器人。 AnythingLLM 存在安全漏洞,该漏洞源于缺少黑白属性名单,允许攻击者未经授权创建高权限帐户。
CVSS信息
N/A
漏洞类别
其他