Skip to main content

Vendor archive

youdao CVEs

Beta · best-effort

5 CVEs tagged to vendor youdao1 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-8027

Published Mar 20, 2025

A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8024

Published Mar 20, 2025

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12866

Published Mar 20, 2025

A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12864

Published Mar 20, 2025

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10264

Published Mar 20, 2025

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1