PT-2024-37185 · Unknown · Gaizhenbiao/Chuanhuchatgpt
Gaizhenbiao
·
Published
2024-10-29
·
Updated
2024-10-31
·
CVE-2024-5823
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
gaizhenbiao/chuanhuchatgpt versions <= 20240410
Description:
A file overwrite issue exists, allowing unauthorized access to overwrite critical configuration files. This can lead to unauthorized changes in system behavior or security settings. Tampering with these files can also result in a denial of service (DoS) condition, disrupting normal system operation.
Recommendations:
For gaizhenbiao/chuanhuchatgpt versions <= 20240410, consider restricting access to critical configuration files to prevent unauthorized overwrites until a patch is available. As a temporary workaround, monitor system behavior and security settings closely for any unauthorized changes.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gaizhenbiao/Chuanhuchatgpt