CVE-2024-3283
HIGHDescription
A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the 'multi_user_mode' system variable, enabling them to access the '/api/system/enable-multi-user' endpoint and create a new admin user. This issue results from the endpoint accepting a full JSON object in the request body without proper validation of modifiable fields, leading to unauthorized modification of system settings and subsequent privilege escalation.
Is your site exposed to CVE-2024-3283?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mintplexlabs | anythingllm |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-3283? +
How severe is CVE-2024-3283? +
What products are affected by CVE-2024-3283? +
How do I check if I'm vulnerable to CVE-2024-3283? +
Related Vulnerabilities
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, …
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, …
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control …
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in …