Description
AnythingLLM is a full-stack app allowing you to build a private ChatGPT using commercial or open-source LLMs and vectorDB solutions, both locally and remotely, for intelligent document chat.
Acunetix determined that it was possible to access AnythingLLM API without authentication.
Remediation
Enable authentication for AnythingLLM
References
Related Vulnerabilities
Error page web server version disclosure
WordPress 6.3.x Multiple Vulnerabilities (6.3 - 6.3.1)
ASP.NET: Failure To Require SSL For Authentication Cookies
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3732)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-14634)