CVE-2024-6090

June 27, 2024, 7:25 p.m.

Awaiting Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

Products

gaizhenbiao/chuanhuchatgpt

  • 20240410

Source

security@huntr.dev

Tags

CVE-2024-6090 details

Published : June 27, 2024, 7:15 p.m.
Last Modified : June 27, 2024, 7:25 p.m.

Description

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.

CVSS Score

1 2 3 4 5 6 7.5 8 9 10

Weakness

Weakness Name Description
CWE-400 Uncontrolled Resource Consumption The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

7.5

Exploitability Score

3.9

Impact Score

3.6

Base Severity

HIGH

References

URL Source
https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c security@huntr.dev
This website uses the NVD API, but is not approved or certified by it.