Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the application's handling of user modifications by managers or admins, allowing for the modification of all existing attributes of the `user` database entity without proper checks or sanitization. This flaw can be exploited to delete user threads, denying users access to their previously submitted data, or to inject fake threads and/or chat history for social engineering attacks.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32836 Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the application's handling of user modifications by managers or admins, allowing for the modification of all existing attributes of the `user` database entity without proper checks or sanitization. This flaw can be exploited to delete user threads, denying users access to their previously submitted data, or to inject fake threads and/or chat history for social engineering attacks.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-01T20:33:53.068Z

Reserved: 2024-04-26T23:49:54.664Z

Link: CVE-2024-4286

cve-icon Vulnrichment

Updated: 2024-08-01T20:33:53.068Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-26T23:15:21.600

Modified: 2024-11-21T09:42:32.600

Link: CVE-2024-4286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses