Vulnerability Description
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerability includes potential phishing attacks, malware distribution, and credential theft.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pribai | Privategpt | 0.5.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/43f05c1e-d7b8-45e2-b1fe-48faf1e3a48dExploitThird Party Advisory
- https://huntr.com/bounties/43f05c1e-d7b8-45e2-b1fe-48faf1e3a48dExploitThird Party Advisory
FAQ
What is CVE-2024-5936?
CVE-2024-5936 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified b...
How severe is CVE-2024-5936?
CVE-2024-5936 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5936?
Check the references section above for vendor advisories and patch information. Affected products include: Pribai Privategpt.