A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-06-27 19:15
Updated : 2024-06-27 19:25
NVD link : CVE-2024-6090
Mitre link : CVE-2024-6090
CVE.ORG link : CVE-2024-6090
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption