← Back to CVE List

CVE-2024-8026

Published: 2025-03-20T10:15Z
Last Modified: 2025-03-26T16:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt