CVE-2024-8400

MEDIUM

gaizhenbiao/chuanhuchatgpt - XSS

Title source: llm
STIX 2.1

Description

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the context of the user's browser.

Scores

CVSS v3 5.4
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
gaizhenbiao/chuanhuchatgpt < 20240410
Published Mar 20, 2025
Tracked Since Feb 18, 2026