Логотип exploitDog
bind:CVE-2024-47171
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-47171

Количество 2

Количество 2

nvd логотип

CVE-2024-47171

больше 1 года назад

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to image file uploads to unauthorized or unintended directories, including overwriting of existing images which may be used for defacement. This does not affect `agnai.chat`, installations using S3-compatible storage, or self-hosting that is not publicly exposed. Version 1.0.330 fixes this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g54f-66mw-hv66

больше 1 года назад

Agnai vulnerable to Relative Path Traversal in Image Upload

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-47171

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to image file uploads to unauthorized or unintended directories, including overwriting of existing images which may be used for defacement. This does not affect `agnai.chat`, installations using S3-compatible storage, or self-hosting that is not publicly exposed. Version 1.0.330 fixes this vulnerability.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-g54f-66mw-hv66

Agnai vulnerable to Relative Path Traversal in Image Upload

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу