U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-4287

Change History

New CVE Received by NIST 5/20/2024 9:15:23 AM

Action Type Old Value New Value
Added CVSS V3

								
							
							
						
huntr.dev AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Added CWE

								
							
							
						
huntr.dev CWE-20
Added Description

								
							
							
						
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slug/update`, allowing it to be executed as part of a database query without restrictions. This flaw enables users with a manager role to craft a request that includes nested write operations, effectively allowing them to create new Administrator accounts.
Added Reference

								
							
							
						
huntr.dev https://github.com/mintplex-labs/anything-llm/commit/94b58249a37a21b1c08deaa2d1edfdecbb6deb18 [No types assigned]
Added Reference

								
							
							
						
huntr.dev https://huntr.com/bounties/34491fb7-5133-4e80-8782-74124350bbdb [No types assigned]