CVE-2024-9159

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly guarded by an admin check.
References
Link Resource
https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-12-04:*:*:*:*:*:*:*

History

01 Aug 2025, 18:19

Type Values Removed Values Added
First Time Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
References () https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a - () https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a - Exploit, Third Party Advisory
CPE cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-12-04:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de autorización incorrecta en la versión git c91dbfc de gaizhenbiao/chuanhuchatgpt. Esta vulnerabilidad permite a cualquier usuario reiniciar el servidor a voluntad, lo que provoca una pérdida total de disponibilidad. El problema surge porque la función responsable de reiniciar el servidor no está debidamente protegida por una comprobación de administrador.

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 18:19


NVD link : CVE-2024-9159

Mitre link : CVE-2024-9159

CVE.ORG link : CVE-2024-9159


JSON object : View

Products Affected

gaizhenbiao

  • chuanhuchatgpt
CWE
CWE-863

Incorrect Authorization