Improper Input Validation in mintplex-labs/anything-llm
CVE-2024-3029
9CRITICAL
What is CVE-2024-3029?
In the Mintplex Labs Anything-LLM application, a serious vulnerability arises due to improper input validation on the '/system/enable-multi-user' endpoint. An attacker can exploit this flaw by sending a specially crafted malformed JSON payload, which triggers an error. The resulting catch block inadvertently deletes all existing user accounts and disables the multi-user feature. This exploitation allows an attacker to not only remove users but also create a new admin user without requiring a password, ultimately leading to unauthorized access and administrative control over the application.
Affected Version(s)
mintplex-labs/anything-llm < 1.0.0