Arbitrary File Read Vulnerability in Gaizhenbiao Chuanhuchatgpt
CVE-2024-7962
7.5HIGH
What is CVE-2024-7962?
An arbitrary file read vulnerability exists in Gaizhenbiao's Chuanhuchatgpt product due to inadequate validation mechanisms when loading prompt template files. This issue permits attackers to read any file that aligns with specific formatting criteria, which includes using absolute paths. Notably, files attempted to be read cannot have a .json extension, and all lines except the first must contain commas. Such vulnerabilities have the potential to expose sensitive information that resides in format-compliant files, which can include critical data such as account credentials, code, and log files.