A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-16585 A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 27 Feb 2025 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Mintplexlabs
Mintplexlabs anythingllm
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mintplexlabs:anythingllm:-:*:*:*:*:*:*:*
Vendors & Products Mintplexlabs
Mintplexlabs anythingllm
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-27T20:43:58.659Z

Reserved: 2024-01-22T22:29:07.144Z

Link: CVE-2024-0798

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.817Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-26T16:27:51.563

Modified: 2025-02-27T03:05:58.637

Link: CVE-2024-0798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.