ChuanhuChatGPT是为ChatGPT/ChatGLM/LLaMA/StableLM/MOSS等多种LLM提供了一个轻快好用的Web图形界面。 ChuanhuChatGPT 20240310及之前版本存在代码问题漏洞,该漏洞源于对上传文件类型的验证不足,允许攻击者上传具有任意扩展名的文件,可能导致存储型跨站脚本攻击以及远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gaizhenbiao | gaizhenbiao/chuanhuchatgpt | unspecified ~ 20240919 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-5124 | Timing Attack Vulnerability in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-3402 | Stored XSS vulnerability in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-3234 | Path Traversal in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-3404 | Improper Access Control in gaizhenbiao/chuanhuchatgpt |
No comments yet