Improper Input Validation in mintplex-labs/anything-llm
CVE-2024-3029

9CRITICAL

Key Information:

Vendor
CVE Published:
16 April 2024

What is CVE-2024-3029?

In the Mintplex Labs Anything-LLM application, a serious vulnerability arises due to improper input validation on the '/system/enable-multi-user' endpoint. An attacker can exploit this flaw by sending a specially crafted malformed JSON payload, which triggers an error. The resulting catch block inadvertently deletes all existing user accounts and disables the multi-user feature. This exploitation allows an attacker to not only remove users but also create a new admin user without requiring a password, ultimately leading to unauthorized access and administrative control over the application.

Affected Version(s)

mintplex-labs/anything-llm < 1.0.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.