A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.
References
Link | Resource |
---|---|
https://huntr.com/bounties/c23da7c7-a226-40a2-83db-6a8ab1b2ef64 | Exploit Third Party Advisory |
Configurations
History
01 Aug 2025, 01:14
Type | Values Removed | Values Added |
---|---|---|
First Time |
Youdao qanything
Youdao |
|
References | () https://huntr.com/bounties/c23da7c7-a226-40a2-83db-6a8ab1b2ef64 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:youdao:qanything:2.0.0:*:*:*:*:*:*:* | |
Summary |
|
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-08-01 01:14
NVD link : CVE-2024-12866
Mitre link : CVE-2024-12866
CVE.ORG link : CVE-2024-12866
JSON object : View
Products Affected
youdao
- qanything
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')