A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.
References
| Link | Resource |
|---|---|
| https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98f98e3965bdb37 | |
| https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e | Exploit Third Party Advisory |
| https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e | Exploit Third Party Advisory |
Configurations
History
15 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CWE | CWE-770 |
15 Jul 2025, 13:19
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| References | () https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e - Exploit, Third Party Advisory | |
| First Time |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
| CPE | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
Information
Published : 2024-07-10 23:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-6037
Mitre link : CVE-2024-6037
CVE.ORG link : CVE-2024-6037
JSON object : View
Products Affected
gaizhenbiao
- chuanhuchatgpt
CWE
