CVE-2024-5823
Last modified
CVE-2024-5823 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security settings. Additionally, tampering with these configuration files can result in a denial of service (DoS) condition, disrupting normal system operation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gaizhenbiao | Chuanhuchatgpt | <= 2024-04-10 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5823?
How severe is CVE-2024-5823?
How do I fix CVE-2024-5823?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5817An Incorrect Authorization vulnerability was identified in G…6.5
- CVE-2024-5818The Royal Elementor Addons and Templates plugin for WordPres…5.4
- CVE-2024-5819The Gutenberg Blocks with AI by Kadence WP – Page Builder Fe…5.4
- CVE-2024-5820An unprotected WebSocket connection in the latest version of…8.8
- CVE-2024-5821The vulnerability allows an attacker to access sensitive fil…6.2
- CVE-2024-5822A Server-Side Request Forgery (SSRF) vulnerability exists in…9.8
- CVE-2024-58237In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-58238In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-58239In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-5824A path traversal vulnerability in the `/set_personality_conf…7.4
- CVE-2024-58240In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-58241In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2024-5823?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
