Vulnerability Description
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gaizhenbiao | Chuanhuchatgpt | 20240410 |
Related Weaknesses (CWE)
References
- https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98
- https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405eExploitThird Party Advisory
- https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405eExploitThird Party Advisory
FAQ
What is CVE-2024-6037?
CVE-2024-6037 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to unc...
How severe is CVE-2024-6037?
CVE-2024-6037 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-6037?
Check the references section above for vendor advisories and patch information. Affected products include: Gaizhenbiao Chuanhuchatgpt.