CVE-2024-0795

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
02/03/2024
Last modified:
21/01/2025

Description

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* 1.0.0 (excluding)