Privilege Escalation in mintplex-labs/anything-llm
Published Feb 25, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.57%
Description
A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplex-Labs | Mintplex-Labs/anything-Llm | n/a |
|
- n/a
-
- Version 0StatusaffectedConstraints<1.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplexlabs | Anythingllm | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
Change history (0)
No recorded changes yet.