Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10819

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 7.1
CVSS3: 8.8
EPSS Низкий

Описание

A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can contain malicious scripts, leading to stored Cross-Site Scripting (XSS) attacks. Through stored XSS, an attacker can steal information about the victim and perform any action on their behalf.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00047
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.1
github
5 месяцев назад

A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can contain malicious scripts, leading to stored Cross-Site Scripting (XSS) attacks. Through stored XSS, an attacker can steal information about the victim and perform any action on their behalf.

EPSS

Процентиль: 14%
0.00047
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352