A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the context of the user's browser.
References
Configurations
History
01 Apr 2025, 20:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/gaizhenbiao/chuanhuchatgpt/commit/2cca68e34f029babbe4eaa5a77d220dad68fdd49 - Patch | |
References | () https://huntr.com/bounties/405f16b8-848e-427d-a61a-ea7d3fd6f0e3 - Exploit | |
First Time |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
CPE | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:* |
20 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/405f16b8-848e-427d-a61a-ea7d3fd6f0e3 - | |
Summary |
|
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-04-01 20:32
NVD link : CVE-2024-8400
Mitre link : CVE-2024-8400
CVE.ORG link : CVE-2024-8400
JSON object : View
Products Affected
gaizhenbiao
- chuanhuchatgpt
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')