In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted curl request with the 'multi_user_mode' parameter set to false, an attacker can deactivate 'Multi-User Mode'. This action permits the creation of a new admin user without requiring a password, leading to unauthorized administrative access.
References
Configurations
No configuration.
History
10 Apr 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-10 17:15
Updated : 2024-04-10 19:49
NVD link : CVE-2024-3101
Mitre link : CVE-2024-3101
CVE.ORG link : CVE-2024-3101
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation