PT-2024-24085 · Docsgpt · Docsgpt

Sylwia-Budzynska

·

Published

2024-04-16

·

Updated

2024-04-19

·

CVE-2024-31451

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions DocsGPT versions prior to 0.8.1
Description The issue is related to an unauthenticated limited file write in routes.py. This allows for unauthorized access to write files, potentially leading to further exploitation. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For versions prior to 0.8.1, update to version 0.8.1 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable routes.py file until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-31451
GHSA-P5QC-VJ2X-9RJP

Affected Products

Docsgpt