A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security settings. Additionally, tampering with these configuration files can result in a denial of service (DoS) condition, disrupting normal system operation.
The vulnerability results from insufficient access control to file paths (CWE-73 — external control of filename, CWE-610 — externally controlled resource reference). An attacker without any credentials can send a network request causing configuration files on the system to be overwritten. Manipulation of these files allows changes to application settings or its security, and in extreme cases leads to disruption of its normal operation.
An attacker can unauthorized overwrite critical configuration files, resulting in changes to the application's behavior or security settings. Further abuse may lead to a denial of service (DoS) state, preventing normal system operation.
The application should be updated to a version containing the fix available in commit 720c23d755a4a955dcb0a54e8c200a2247a27f8b in the manufacturer's GitHub repository. It is also recommended to restrict network access to application instances and review permissions for critical configuration files.
gaizhenbiao/ChuanhuChatGPT in versions <= 20240410
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HGaizhenbiao Chuanhuchatgpt
APPGaizhenbiao≤ 2024-04-10
Related vulnerabilities
Path Traversal i RCE w ChuanhuChatGPT — niezabezpieczone dane wejściowe
Nieautoryzowany restart serwera w ChuanhuChatGPT poprzez endpoint /queue/join
Tworzenie arbitralnych folderów na serwerze w ChuanhuChatGPT
SSRF w interfejsie upload ChuanhuChatGPT — dostęp do zasobów wewnętrznych
Path traversal w ChuanhuChatGPT — dostęp do poufnych plików