CVE-2024-8143
MEDIUMgaizhenbiao/chuanhuchatgpt <20240628 - Privilege Escalation
Title source: llmDescription
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/71c5ea4b-524a-4173-8fd4-2fbabd69502e
Scores
CVSS v3
4.3
EPSS
0.0019
EPSS Percentile
41.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1057
Status
published
Products (1)
gaizhenbiao/chuanhuchatgpt
2024-06-28
Published
Oct 29, 2024
Tracked Since
Feb 18, 2026