CVE-2024-8024 Information
Mar 21, 2025
cve
Description
A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.
Reference
https://huntr.com/bounties/bda53fab-88aa-4e03-8d9d-4cf50a98ffc7
Share on: