A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.
An attacker, without the need for authentication, can send network requests that cause arbitrary folders to be created anywhere in the server's file system — including the root directory (e.g., C:\). Lack of proper control over resource creation (CWE-770) allows uncontrolled consumption of system resources. Mass creation of folders can lead to exhaustion of available disk space or file system limits, resulting in denial of service (DoS).
An attacker can cause server resource exhaustion, unavailability (DoS), and potential data loss or corruption. It is also possible to disrupt the integrity of the file system structure by writing to critical locations.
The application should be updated to a version containing the patch available in the manufacturer's repository (commit 71cb89c4c948dae5aaa0ae64b98f98e3965bdb37 on GitHub). Patches available from the manufacturer should be applied according to the references.
ChuanhuChatGPT (gaizhenbiao/chuanhuchatgpt) in version 20240410
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HGaizhenbiao Chuanhuchatgpt
APPGaizhenbiao20240410
Related vulnerabilities
Path Traversal i RCE w ChuanhuChatGPT — niezabezpieczone dane wejściowe
Nadpisanie plików konfiguracyjnych w ChuanhuChatGPT (file overwrite)
Nieautoryzowany restart serwera w ChuanhuChatGPT poprzez endpoint /queue/join
SSRF w interfejsie upload ChuanhuChatGPT — dostęp do zasobów wewnętrznych
Path traversal w ChuanhuChatGPT — dostęp do poufnych plików