Vulnerability Description
A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large filename, causing the server to become overwhelmed and unavailable for legitimate users. This attack does not require authentication, making it highly scalable and increasing the risk of exploitation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Youdao | Qanything | 2.0.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/365c3b9a-180c-4bb5-98d8-dbd78d93fcb7ExploitThird Party Advisory
FAQ
What is CVE-2024-12864?
CVE-2024-12864 is a vulnerability with a CVSS score of 7.5 (HIGH). A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large fi...
How severe is CVE-2024-12864?
CVE-2024-12864 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-12864?
Check the references section above for vendor advisories and patch information. Affected products include: Youdao Qanything.