CVE-2024-6037

CRITICAL

Gaizhenbiao Chuanhuchatgpt - Resource Allocation Without Limits

Title source: rule
STIX 2.1

Description

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.

Scores

CVSS v3 9.1
EPSS 0.0361
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (1)
gaizhenbiao/chuanhuchatgpt 20240410
Published Jul 10, 2024
Tracked Since Feb 18, 2026