CVE-2024-0763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/02/2024
Last modified:
27/03/2025

Description

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* 1.0.0 (excluding)