CVE-2024-8026

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qanything:qanything:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-20 10:15

Updated : 2025-03-26 16:26


NVD link : CVE-2024-8026

Mitre link : CVE-2024-8026

CVE.ORG link : CVE-2024-8026


JSON object : View

Products Affected

qanything

  • qanything
CWE
CWE-352

Cross-Site Request Forgery (CSRF)