CVE-2024-9159

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly guarded by an admin check.
References
Link Resource
https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-12-04:*:*:*:*:*:*:*

History

01 Aug 2025, 18:19

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de autorización incorrecta en la versión git c91dbfc de gaizhenbiao/chuanhuchatgpt. Esta vulnerabilidad permite a cualquier usuario reiniciar el servidor a voluntad, lo que provoca una pérdida total de disponibilidad. El problema surge porque la función responsable de reiniciar el servidor no está debidamente protegida por una comprobación de administrador.
CPE cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-12-04:*:*:*:*:*:*:*
First Time Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
References () https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a - () https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 18:19


NVD link : CVE-2024-9159

Mitre link : CVE-2024-9159

CVE.ORG link : CVE-2024-9159


JSON object : View

Products Affected

gaizhenbiao

  • chuanhuchatgpt
CWE
CWE-863

Incorrect Authorization