A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large filename, causing the server to become overwhelmed and unavailable for legitimate users. This attack does not require authentication, making it highly scalable and increasing the risk of exploitation.
References
Link | Resource |
---|---|
https://huntr.com/bounties/365c3b9a-180c-4bb5-98d8-dbd78d93fcb7 | Exploit Third Party Advisory |
Configurations
History
01 Aug 2025, 10:51
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:youdao:qanything:2.0.0:*:*:*:*:*:*:* | |
First Time |
Youdao qanything
Youdao |
31 Jul 2025, 18:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/365c3b9a-180c-4bb5-98d8-dbd78d93fcb7 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:qanything:qanything:2.0.0:*:*:*:*:*:*:* | |
First Time |
Qanything qanything
Qanything |
|
Summary |
|
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-08-01 10:51
NVD link : CVE-2024-12864
Mitre link : CVE-2024-12864
CVE.ORG link : CVE-2024-12864
JSON object : View
Products Affected
youdao
- qanything
CWE
CWE-400
Uncontrolled Resource Consumption