CVE-2024-6841
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-6841 is a newly identified Cross-Site Request Forgery (CSRF) vulnerability affecting the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app, which provide SQL functionality, are implemented as simple GET requests, making them susceptible to CSRF attacks. An attacker can exploit this vulnerability to run arbitrary SQL commands without the target's knowledge or consent, resulting in data alteration or deletion. The impact of this vulnerability is limited to the affected system, with the attacker unable to read query results.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.