CVE-2024-12864
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-12864 is a newly discovered Denial of Service (DoS) vulnerability affecting the file upload feature of netease-youdao/qanything version v2.0.0. The issue arises from the server's improper handling of form-data with oversized filenames in upload requests. An attacker can exploit this vulnerability by sending a large filename, leading the server to become overloaded and unresponsive, denying service to legitimate users. No authentication is required for this attack, thereby increasing the threat's scalability and the likelihood of successful exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.