Skip to main content

Vendor archive

gaizhenbiao CVEs

Beta · best-effort

31 CVEs tagged to vendor gaizhenbiao6 Critical, 12 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2024-3404

Published Jun 6, 2024

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3402

Published Jun 6, 2024

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. D…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3234

Published Jun 6, 2024

The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user ac…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-4520

Published Jun 4, 2024

An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4321

Published May 16, 2024

A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerabilit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2217

Published Apr 10, 2024

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-31 of 31 CVEsPage 2 of 2