← Back

CVE-2024-13060

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.

Affected (1)

1 product
Anythingllm Docker
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.3.1

Timeline

No history available yet.