github.com
https://github.com/gaizhenbiao/chuanhuchatgpt/commit/2cca68e34f029babbe4eaa5a77d220dad68fdd49 CVE-2024-8400
MEDIUM
Stored XSS in gaizhenbiao/chuanhuchatgpt
Record summary
CVE-2024-8400 has a selected CVSS score of 5.4 (medium).
Description
A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the context of the user's browser.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
gaizhenbiao/chuanhuchatgptBrowse gaizhenbiao / gaizhenbiao/chuanhuchatgpt | CVE List | Before 20240410 | affected |
References
3huntr.com
https://huntr.com/bounties/405f16b8-848e-427d-a61a-ea7d3fd6f0e3 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8400