Back

HIGH

Privilege Escalation via Mass Assignment in mintplex-labs/anything-llm

Published Apr 10, 2024

Description

A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the 'multi_user_mode' system variable, enabling them to access the '/api/system/enable-multi-user' endpoint and create a new admin user. This issue results from the endpoint accepting a full JSON object in the request body without proper validation of modifiable fields, leading to unauthorized modification of system settings and subsequent privilege escalation.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Apr 10, 2024
Updated Aug 12, 2024
Reserved Apr 3, 2024
CISA Vulnrichment
Updated Apr 15, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner @huntr_ai
Published Apr 10, 2024
Updated Aug 12, 2024
Exploited since n/a
EUVD-2024-31873