Cross-Site Request Forgery Vulnerability in PrivateGPT by Imartinez
CVE-2024-5935

5.4MEDIUM

Key Information:

Vendor

Zylon

Vendor
CVE Published:
27 June 2024

What is CVE-2024-5935?

A vulnerability in PrivateGPT, specifically in version 0.5.0, allows for Cross-Site Request Forgery (CSRF) attacks. This security gap enables an attacker to execute unauthorized requests on behalf of authenticated users, leading to the potential deletion of all uploaded files. The implications of this vulnerability are severe, as it can result in significant data loss and disrupt the service for users relying on the application. Prompt attention to patching this vulnerability is crucial to safeguard user data and maintain application integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.