Back

MEDIUM

Privilege Escalation in mintplex-labs/anything-llm

Published Feb 25, 2024

Description

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Feb 25, 2024
Updated Aug 27, 2024
Reserved Jan 22, 2024
CISA Vulnrichment
Updated Aug 27, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner @huntr_ai
Published Feb 25, 2024
Updated Aug 27, 2024
Exploited since n/a
EUVD-2024-16585