ChuanhuChatGPT是Chuan Hu个人开发者的一款应用程序。为 ChatGPT 等多种 LLM 提供了一个轻快好用的 Web 图形界面和众多附加功能 ChuanhuChatGPT 20240914版本存在代码问题漏洞,该漏洞源于允许攻击者通过保存响应到以目标URL的SHA-1哈希命名的文件夹中构造响应链接,可能导致服务端请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gaizhenbiao | gaizhenbiao/chuanhuchatgpt | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0191 | Denial of Service in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-8400 | Stored XSS in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-8613 | Improper Access Control in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-10650 | Denial of Service (DoS) in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-10955 | ReDoS (Regular Expression Denial of Service) in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-10707 | Local File Inclusion in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-9159 | Incorrect Authorization in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-9107 | Stored XSS in gaizhenbiao/chuanhuchatgpt | |
| CVE-2024-9216 | Authentication Bypass in gaizhenbiao/ChuanhuChatGPT |
No comments yet