CVE-2024-8613

HIGH

gaizhenbiao/chuanhuchatgpt 20240802 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.

Scores

CVSS v3 8.8
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
gaizhenbiao/chuanhuchatgpt 20240802
Published Mar 20, 2025
Tracked Since Feb 18, 2026