A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security settings. Additionally, tampering with these configuration files can result in a denial of service (DoS) condition, disrupting normal system operation.
References
Link | Resource |
---|---|
https://github.com/gaizhenbiao/chuanhuchatgpt/commit/720c23d755a4a955dcb0a54e8c200a2247a27f8b | Patch |
https://huntr.com/bounties/ca361701-7d68-4df6-8da0-caad4b85b9ae | Exploit Third Party Advisory |
Configurations
History
31 Oct 2024, 18:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/gaizhenbiao/chuanhuchatgpt/commit/720c23d755a4a955dcb0a54e8c200a2247a27f8b - Patch | |
References | () https://huntr.com/bounties/ca361701-7d68-4df6-8da0-caad4b85b9ae - Exploit, Third Party Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
CWE | CWE-610 | |
First Time |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
29 Oct 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-29 13:15
Updated : 2024-10-31 18:05
NVD link : CVE-2024-5823
Mitre link : CVE-2024-5823
CVE.ORG link : CVE-2024-5823
JSON object : View
Products Affected
gaizhenbiao
- chuanhuchatgpt