A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This issue arises due to improper validation of file paths, enabling directory traversal attacks. An attacker can exploit this vulnerability to disrupt the functioning of the system, manipulate settings, or potentially cause data loss or corruption.
History

Fri, 30 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_0

{'score': 8.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Fri, 30 Aug 2024 15:45:00 +0000

Type Values Removed Values Added
Title Arbitrary File Deletion via Directory Traversal in gaizhenbiao/chuanhuchatgpt Path Traversal in gaizhenbiao/chuanhuchatgpt
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Tue, 27 Aug 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
Weaknesses CWE-22
CPEs cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*
Vendors & Products Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-07-31T00:00:15.258Z

Updated: 2024-08-30T15:29:49.126Z

Reserved: 2024-06-21T18:37:27.016Z

Link: CVE-2024-6255

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.443Z

cve-icon NVD

Status : Modified

Published: 2024-07-31T01:15:09.847

Modified: 2024-08-30T16:15:10.467

Link: CVE-2024-6255

cve-icon Redhat

No data.