CVE-2024-8026

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:*

History

26 Mar 2025, 16:26

Type Values Removed Values Added
First Time Qanything qanything
Qanything
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:*
References () https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274 - () https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274 - Exploit, Third Party Advisory

20 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-352

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-03-26 16:26


NVD link : CVE-2024-8026

Mitre link : CVE-2024-8026


JSON object : View

Products Affected

qanything

  • qanything
CWE

No CWE.