A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, allowing for the injection and execution of malicious JavaScript code within the context of a user's browser. This vulnerability can lead to the execution of arbitrary JavaScript code in the context of other users' browsers, potentially resulting in the hijacking of victims' browsers.
History

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
CPEs cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:*
Vendors & Products Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-06T18:24:03.274Z

Updated: 2024-08-01T20:12:06.645Z

Reserved: 2024-04-05T17:58:36.003Z

Link: CVE-2024-3402

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:06.645Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T19:16:01.450

Modified: 2024-11-21T09:29:31.370

Link: CVE-2024-3402

cve-icon Redhat

No data.