Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8143

Опубликовано: 29 окт. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 4.3
EPSS Низкий

Описание

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-06-28:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00144
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-1057
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.

EPSS

Процентиль: 35%
0.00144
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-1057
NVD-CWE-noinfo