CVE-2024-3283
HIGHAnythingLLM < 1.0.0 - Authenticated Privilege Escalation via Mass Assignment in Admin System Preferences
Title source: llmDescription
A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the 'multi_user_mode' system variable, enabling them to access the '/api/system/enable-multi-user' endpoint and create a new admin user. This issue results from the endpoint accepting a full JSON object in the request body without proper validation of modifiable fields, leading to unauthorized modification of system settings and subsequent privilege escalation.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/a8000cce-0ecb-4820-9cfb-57ba6f4d58a2
Scores
CVSS v3
7.2
EPSS
0.0095
EPSS Percentile
56.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-915
Status
published
Products (1)
mintplexlabs/anythingllm
< 1.0.0
Published
Apr 10, 2024
Tracked Since
Feb 18, 2026