CVE-2024-8026

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:*

History

26 Mar 2025, 16:26

Type Values Removed Values Added
CPE cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Request Forgery (CSRF) en la API de backend de netease-youdao/qanything, a partir del commit d9ab8bc. El servidor backend tiene encabezados CORS excesivamente permisivos, lo que permite todas las llamadas de origen cruzado. Esta vulnerabilidad afecta a todos los endpoints del backend, lo que permite acciones como crear, subir, listar, eliminar archivos y administrar bases de conocimiento.
First Time Qanything qanything
Qanything
References () https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274 - () https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274 - Exploit, Third Party Advisory

20 Mar 2025, 16:15

Type Values Removed Values Added
References () https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274 - () https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274 -

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-03-26 16:26


NVD link : CVE-2024-8026

Mitre link : CVE-2024-8026

CVE.ORG link : CVE-2024-8026


JSON object : View

Products Affected

qanything

  • qanything
CWE
CWE-352

Cross-Site Request Forgery (CSRF)