Local File Inclusion Vulnerability in ChuanhuChatGPT by Gaizhenbiao
CVE-2024-10707
6.5MEDIUM
What is CVE-2024-10707?
The ChuanhuChatGPT application, developed by Gaizhenbiao, is vulnerable to a local file inclusion issue stemming from the use of the gradio component's gr.JSON functionality. This vulnerability emerges from inadequate input validation in the handle_dataset_selection method, enabling unauthenticated attackers to upload crafted JSON files that can reveal arbitrary files from the server, compromising its integrity and confidentiality.
Affected Version(s)
gaizhenbiao/chuanhuchatgpt <= unspecified