Description
AnythingLLM is a full-stack app allowing you to build a private ChatGPT using commercial or open-source LLMs and vectorDB solutions, both locally and remotely, for intelligent document chat.
Acunetix determined that it was possible to access AnythingLLM API without authentication.
Remediation
Enable authentication for AnythingLLM
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3848)
Phpfastcache phpinfo publicly accessible (CVE-2021-37704)
Oracle E-Business Suite Frame Injection (CVE-2017-3528)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4999)