CVE-2024-0765
Mintplexlabs
CVE-2024-0765 allows unauthorized data exfiltration in AnythingLLM. A default user can exploit the /export-data
endpoint to download sensitive system data. This vulnerability highlights the importance of robust access control.
CVE-2024-0765 is a medium severity vulnerability (CVSS 6.5), enabling a user with even minimal access to exfiltrate data. The low SOCRadar Vulnerability Risk Score (SVRS) of 34 suggests that active exploitation is not currently widespread. However, successful exploitation allows exfiltration without leaving a trace. Mitigation should focus on restricting access to the /export-data
endpoint and implementing robust auditing. This could lead to sensitive information exposure. While not immediately critical, the ease of exploitation makes it a significant risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.