Podatność CVE-2024-0550


Publikacja: 2024-02-28

Opis:
A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files.

The attacker would have to have been granted privileged permissions to the system before executing this attack.

Typ:

CWE-23

(Relative Path Traversal)

 Referencje:
https://huntr.com/bounties/c6afeb5e-f211-4b3d-aa4b-6bad734217a6
https://github.com/mintplex-labs/anything-llm/commit/e1dcd5ded010b03abd6aa32d1bf0668a48e38e17

Copyright 2024, cxsecurity.com

 

Back to Top