CVE-2024-8613 is a high-severity vulnerability (CVSS 8.8) affecting gaizhenbiao/chuanhuchatgpt version 20240802. It stems from improper session data handling and a lack of access control, allowing authenticated attackers to access, copy, and delete other users' chat histories. This presents a significant risk of confidentiality, integrity, and availability compromise for user data. The attack vector is network-based with low attack complexity, requiring only low privileges to exploit, and no user interaction. While the FAUCET Risk Score is high at 83/100, there is currently no evidence of active exploitation, nor are there any public exploit modules or proof-of-concept code available. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20240802CPE matchmatch criteria | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240802:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.