CVE-2024-12866
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:11:31
- Zuletzt bearbeitet 01.08.2025 01:14:38
A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading ...
CVE-2024-12864
- EPSS 0.64%
- Veröffentlicht 20.03.2025 10:10:47
- Zuletzt bearbeitet 01.08.2025 10:51:13
A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can...
CVE-2024-8027
- EPSS 0.04%
- Veröffentlicht 20.03.2025 10:10:30
- Zuletzt bearbeitet 01.08.2025 01:46:37
A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during user chats. This vulnerability affects all versions prior...
CVE-2024-8024
- EPSS 0.03%
- Veröffentlicht 20.03.2025 10:10:09
- Zuletzt bearbeitet 01.08.2025 01:45:39
A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive...
CVE-2024-10264
- EPSS 0.13%
- Veröffentlicht 20.03.2025 10:10:04
- Zuletzt bearbeitet 01.08.2025 10:51:56
HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security c...