A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Qanything
Qanything qanything |
|
CPEs | cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:* | |
Vendors & Products |
Qanything
Qanything qanything |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases. | |
Title | CSRF due to overly permissive CORS headers in netease-youdao/qanything | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:03.731Z
Updated: 2025-03-20T15:49:53.923Z
Reserved: 2024-08-20T18:40:00.477Z
Link: CVE-2024-8026

Updated: 2025-03-20T15:49:50.432Z

Status : Analyzed
Published: 2025-03-20T10:15:39.503
Modified: 2025-03-26T16:26:39.410
Link: CVE-2024-8026

No data.