A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server restart capability can severely disrupt service availability, cause data loss or corruption, and potentially compromise system integrity.
The attacker sends a specially crafted HTTP request to the `/queue/join?` endpoint with the parameter `"fn_index":66`. The application does not verify the permissions or identity of the requester, allowing any network user to execute the server restart operation. The lack of any access control to this function makes the attack trivial to perform and requires no authentication.
An attacker can repeatedly restart the server, causing continuous service disruptions (DoS), potential loss or corruption of processed data, and violation of system integrity.
Patches available from the vendor should be applied in accordance with the references. Additionally, it is recommended to restrict access to the `/queue/join` endpoint at the firewall or reverse proxy level and implement authentication mechanisms for sensitive administrative functions.
gaizhenbiao/ChuanhuChatGPT version 20240410
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HGaizhenbiao Chuanhuchatgpt
APPGaizhenbiao20240410
Related vulnerabilities
Path Traversal i RCE w ChuanhuChatGPT — niezabezpieczone dane wejściowe
Nadpisanie plików konfiguracyjnych w ChuanhuChatGPT (file overwrite)
Tworzenie arbitralnych folderów na serwerze w ChuanhuChatGPT
SSRF w interfejsie upload ChuanhuChatGPT — dostęp do zasobów wewnętrznych
Path traversal w ChuanhuChatGPT — dostęp do poufnych plików