In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 31 Oct 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-06-28:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
| CPEs | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240628:*:*:*:*:*:*:* | |
| Vendors & Products |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
| Metrics |
ssvc
|
Tue, 29 Oct 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history. | |
| Title | Unauthorized Access to User Chat History in gaizhenbiao/chuanhuchatgpt | |
| Weaknesses | CWE-1057 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-29T12:49:09.525Z
Updated: 2024-10-29T13:23:01.857Z
Reserved: 2024-08-24T00:08:38.146Z
Link: CVE-2024-8143
Updated: 2024-10-29T13:22:55.555Z
Status : Analyzed
Published: 2024-10-29T13:15:10.750
Modified: 2024-10-31T16:23:35.827
Link: CVE-2024-8143
No data.