Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2h96-7jv3-737m

Опубликовано: 29 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.

EPSS

Процентиль: 35%
0.00144
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1057

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.

EPSS

Процентиль: 35%
0.00144
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1057