CVE-2024-3102 is a JSON Injection vulnerability affecting mintplex-labs/anything-llm, specifically in the username parameter of the login process at the /api/request-token endpoint. This allows attackers to brute-force usernames without prior knowledge and, once a password is known, conduct blind attacks to determine the full username. Rated Medium severity with a CVSS score of 5.3, this vulnerability has a low attack complexity and no user interaction required, potentially leading to a compromise of confidentiality. The primary impact is information disclosure of usernames. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.