Vulnerabilities > Gaizhenbiao > Chuanhuchatgpt > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-5982 Path Traversal vulnerability in Gaizhenbiao Chuanhuchatgpt
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt.
network
low complexity
gaizhenbiao CWE-22
critical
9.8
2024-10-29 CVE-2024-5823 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Gaizhenbiao Chuanhuchatgpt
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410.
network
low complexity
gaizhenbiao CWE-610
critical
9.1
2024-07-31 CVE-2024-6255 Unspecified vulnerability in Gaizhenbiao Chuanhuchatgpt 20240410
A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`.
network
low complexity
gaizhenbiao
critical
9.1
2024-06-06 CVE-2024-3234 Unspecified vulnerability in Gaizhenbiao Chuanhuchatgpt
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component.
network
low complexity
gaizhenbiao
critical
9.8