Логотип exploitDog
bind:CVE-2024-10902
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-10902

Количество 2

Количество 2

nvd логотип

CVE-2024-10902

11 месяцев назад

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xq5-x4fj-rff7

11 месяцев назад

DB-GPT vulnerable to Arbitrary File Upload with Path Traversal

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-10902

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.

CVSS3: 9.8
3%
Низкий
11 месяцев назад
github логотип
GHSA-3xq5-x4fj-rff7

DB-GPT vulnerable to Arbitrary File Upload with Path Traversal

CVSS3: 9.1
3%
Низкий
11 месяцев назад

Уязвимостей на страницу