A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values, allowing attackers to perform brute force attacks without prior knowledge of the username. Once the password is known, attackers can conduct blind attacks to ascertain the full username, significantly compromising system security.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Sun, 03 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-229 | 
Sun, 03 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:mintplexlabs:anythingllm:-:*:*:*:*:*:*:* | |
| Metrics | ssvc 
 | 
Tue, 22 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Mintplexlabs Mintplexlabs anythingllm | |
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* | |
| Vendors & Products | Mintplexlabs Mintplexlabs anythingllm | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T18:19:23.450Z
Updated: 2024-11-03T18:27:23.547Z
Reserved: 2024-03-29T18:43:30.670Z
Link: CVE-2024-3102
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T19:32:42.847Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-06-06T19:15:59.667
Modified: 2024-11-21T09:28:54.413
Link: CVE-2024-3102
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow