netease-youdao qanything Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The vulnerability arises from overly permissive CORS headers that allow all cross-origin requests. This issue impacts all backend endpoints, enabling unauthorized actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
Impact
Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to perform actions on behalf of users without their consent. In this case, it could involve unauthorized file management and knowledge base administration.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
