ZeroHour

CVE-2024-13060

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p40
Published
()
Modified
Description

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.

Vendors
mintplexlabs
Products
anythingllm docker
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.