CORS Misconfiguration in Netease Youdao Qanything
CVE-2024-8024
7.5HIGH
What is CVE-2024-8024?
A CORS misconfiguration vulnerability is present in Netease Youdao Qanything version 1.4.1. This flaw allows attackers to circumvent the Same-Origin Policy, which can lead to unintended exposure of sensitive information. To safeguard against such vulnerabilities, it is essential to adopt a properly restrictive CORS policy, ensuring that only authorized domains can access your resources.
Affected Version(s)
netease-youdao/qanything <= unspecified
