CVE-2024-0550 CRITICAL

CVE-2024-0550: Privileged User using traversal to read system files

Vendor Mintplex-Labs
Product mintplex-labs/anything-llm
Weakness CWE-23
Published February 28, 2024
Last update August 22, 2024

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.

Key dates

02Disclosure timeline

February 28, 2024 CVE published
August 22, 2024 Record updated

Related vulnerabilities

04Related CVE