Vulnerability Description
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server restart capability can severely disrupt service availability, cause data loss or corruption, and potentially compromise system integrity.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gaizhenbiao | Chuanhuchatgpt | 20240410 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/e9eaaea9-5750-4955-9142-2f12ad4b06dbExploitThird Party Advisory
- https://huntr.com/bounties/e9eaaea9-5750-4955-9142-2f12ad4b06dbExploitThird Party Advisory
FAQ
What is CVE-2024-6036?
CVE-2024-6036 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unr...
How severe is CVE-2024-6036?
CVE-2024-6036 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-6036?
Check the references section above for vendor advisories and patch information. Affected products include: Gaizhenbiao Chuanhuchatgpt.