Vulnerability Description
gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malicious JavaScript is executed in the victim's browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gaizhenbiao | Chuanhuchatgpt | <= 20240802 |
Related Weaknesses (CWE)
References
- https://gist.github.com/AfterSnows/c5a4cb029fb9142be5c54e531a9a240eThird Party Advisory
- https://rumbling-slice-eb0.notion.site/Stored-XSS-via-Chat-message-in-gaizhenbiaExploit
FAQ
What is CVE-2024-48059?
CVE-2024-48059 is a vulnerability with a CVSS score of 6.1 (MEDIUM). gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket m...
How severe is CVE-2024-48059?
CVE-2024-48059 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48059?
Check the references section above for vendor advisories and patch information. Affected products include: Gaizhenbiao Chuanhuchatgpt.