HIGH
Path Traversal Vulnerability in gaizhenbiao/chuanhuchatgpt
Published Jun 27, 2024
7.5
HIGHCVSS 3.0
EPSS 0.86%
Description
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<20240918
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Gaizhenbiao | Gaizhenbiao/chuanhuchatgpt | n/a |
|
- 20240410
-
- Version 20240410StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Gaizhenbiao | Chuanhuchatgpt | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47245 Advisory
- https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705
- https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47245 | Advisory | |
| https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705 | ||
| https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Jun 27, 2024
Updated Oct 15, 2025
Reserved Jun 17, 2024
Link CVE-2024-6090
CISA Vulnrichment
Updated Jun 27, 2024
ENISA EUVD
EUVD-2024-47245 Assigner @huntr_ai
Published Jun 27, 2024
Updated Oct 15, 2025
Exploited since n/a
Link EUVD-2024-47245