CVE-2024-13060
Published Mar 20, 2025A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cooki…
Vendor/product archive
2 CVEs tagged to mintplexlabs / anythingllm_docker — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cooki…
A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application…