A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This issue arises due to improper validation of file paths, enabling directory traversal attacks. An attacker can exploit this vulnerability to disrupt the functioning of the system, manipulate settings, or potentially cause data loss or corruption.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-73 | |
Metrics |
cvssV3_0
|
Fri, 30 Aug 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Arbitrary File Deletion via Directory Traversal in gaizhenbiao/chuanhuchatgpt | Path Traversal in gaizhenbiao/chuanhuchatgpt |
Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 27 Aug 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:* | |
Vendors & Products |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-07-31T00:00:15.258Z
Updated: 2024-08-30T15:29:49.126Z
Reserved: 2024-06-21T18:37:27.016Z
Link: CVE-2024-6255
Vulnrichment
Updated: 2024-08-01T21:33:05.443Z
NVD
Status : Modified
Published: 2024-07-31T01:15:09.847
Modified: 2024-11-21T09:49:17.200
Link: CVE-2024-6255
Redhat
No data.