github.com
https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705 CVE-2024-6090
HIGH
Path Traversal Vulnerability in gaizhenbiao/chuanhuchatgpt
Record summary
CVE-2024-6090 has a selected CVSS score of 7.5 (high).
Description
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
chuanhuchatgptBrowse gaizhenbiao / chuanhuchatgptDefault status: unknown | CVE List | 20240410 | affected |
gaizhenbiao/chuanhuchatgptBrowse gaizhenbiao / gaizhenbiao/chuanhuchatgpt | CVE List | Before 20240918 | affected |
References
3huntr.com
https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6090