Arbitrary Folder Creation Vulnerability in Gaizhenbiao's Chuanhuchatgpt
CVE-2024-6037

7.5HIGH

Key Information:

Vendor
CVE Published:
10 July 2024

What is CVE-2024-6037?

A security vulnerability exists within Gaizhenbiao's ChuanhuChatGPT version 20240410, allowing malicious actors to create arbitrary directories on the server operating system. This issue leads to significant risks, including uncontrolled consumption of server resources, which can ultimately result in service disruptions and potential denial of service (DoS). The exploit allows attackers to manipulate folder structures in sensitive areas, including the root directory (C: dir), posing risks of data loss or corruption caused by poor resource management and server instability.

Affected Version(s)

gaizhenbiao/chuanhuchatgpt <= unspecified

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.