CVE-2024-10359 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through m…
Medium CVSS: 4.6

CVE-2024-10359

In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of another user. The vulnerability arises because the backend saves the entire object received without validating the attributes and their values, impacting both integrity and confidentiality.
Vendor
Librechat
Product
Librechat
CWE
CWE-915
Yayın Tarihi
2025-03-20 10:15:16
Güncelleme
2025-07-11 20:32:31
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar