CVE-2024-6037

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*

History

15 Oct 2025, 13:15

Type Values Removed Values Added
References
  • () https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98f98e3965bdb37 -
CWE CWE-400 CWE-770

15 Jul 2025, 13:19

Type Values Removed Values Added
First Time Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.1
References () https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e - () https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e - Exploit, Third Party Advisory
CPE cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*

21 Nov 2024, 09:48

Type Values Removed Values Added
References () https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e - () https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e -

11 Jul 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en gaizhenbiao/chuanhuchatgpt versión 20240410 permite a un atacante crear carpetas arbitrarias en cualquier ubicación del servidor, incluido el directorio raíz (C: dir). Esto puede conducir a un consumo incontrolado de recursos, lo que resulta en agotamiento de recursos, denegación de servicio (DoS), indisponibilidad del servidor y posible pérdida o corrupción de datos.

10 Jul 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-10 23:15

Updated : 2025-10-15 13:15


NVD link : CVE-2024-6037

Mitre link : CVE-2024-6037

CVE.ORG link : CVE-2024-6037


JSON object : View

Products Affected

gaizhenbiao

  • chuanhuchatgpt
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

NVD-CWE-noinfo