漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unrestricted File Upload leading to RCE in gaizhenbiao/chuanhuchatgpt
Vulnerability Description
gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function does not sanitize or validate the file extension or content type of uploaded files, allowing attackers to upload files with arbitrary extensions, including HTML files containing XSS payloads and Python files. This vulnerability, present in the latest version as of 20240310, could lead to stored XSS attacks and potentially result in remote code execution (RCE) on the server hosting the application.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
ChuanhuChatGPT 代码问题漏洞
Vulnerability Description
ChuanhuChatGPT是为ChatGPT/ChatGLM/LLaMA/StableLM/MOSS等多种LLM提供了一个轻快好用的Web图形界面。 ChuanhuChatGPT 20240310及之前版本存在代码问题漏洞,该漏洞源于对上传文件类型的验证不足,允许攻击者上传具有任意扩展名的文件,可能导致存储型跨站脚本攻击以及远程代码执行(RCE)。
CVSS Information
N/A
Vulnerability Type
N/A