A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.
References
Configurations
History
No history.
Information
Published : 2024-06-27 19:15
Updated : 2024-11-21 09:48
NVD link : CVE-2024-5935
Mitre link : CVE-2024-5935
CVE.ORG link : CVE-2024-5935
JSON object : View
Products Affected
zylon
- privategpt
CWE
CWE-352
Cross-Site Request Forgery (CSRF)