ZeroHour

CVE-2024-0763

PoC
CVSS 3.1
8.1 high
EPSS
<1%p58
Published
()
Modified
Description

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.

Vendors
mintplexlabs
Products
anythingllm
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.