A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
History

Wed, 26 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Qanything
Qanything qanything
CPEs cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:*
Vendors & Products Qanything
Qanything qanything
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Thu, 20 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
Title CSRF due to overly permissive CORS headers in netease-youdao/qanything
Weaknesses CWE-352
References
Metrics cvssV3_0

{'score': 8.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:11:03.731Z

Updated: 2025-03-20T15:49:53.923Z

Reserved: 2024-08-20T18:40:00.477Z

Link: CVE-2024-8026

cve-icon Vulnrichment

Updated: 2025-03-20T15:49:50.432Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:39.503

Modified: 2025-03-26T16:26:39.410

Link: CVE-2024-8026

cve-icon Redhat

No data.