CVE-2024-0763 Information
Feb 29, 2024
cve
Description
Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.
Reference
https://huntr.com/bounties/25a2f487-5a9c-4c7f-a2d3-b0527db73ea5 https://github.com/mintplex-labs/anything-llm/commit/8a7324d0e77a15186e1ad5e5119fca4fb224c39c
Share on: