We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-8400

Stored XSS in gaizhenbiao/chuanhuchatgpt



Description

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the context of the user's browser.

Reserved 2024-09-03 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 5.4CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Any version before 20240410
affected

References

huntr.com/bounties/405f16b8-848e-427d-a61a-ea7d3fd6f0e3

github.com/...ommit/2cca68e34f029babbe4eaa5a77d220dad68fdd49

cve.org (CVE-2024-8400)

nvd.nist.gov (CVE-2024-8400)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-8400

Support options

Helpdesk Chat, Email, Knowledgebase