CVE-2024-9159

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly guarded by an admin check.
CVSS

No CVSS.

References
Link Resource
https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-12-04:*:*:*:*:*:*:*

History

01 Aug 2025, 18:19

Type Values Removed Values Added
References () https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a - () https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a - Exploit, Third Party Advisory
CPE cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:2024-12-04:*:*:*:*:*:*:*
First Time Gaizhenbiao
Gaizhenbiao chuanhuchatgpt

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 18:19


NVD link : CVE-2024-9159

Mitre link : CVE-2024-9159


JSON object : View

Products Affected

gaizhenbiao

  • chuanhuchatgpt
CWE
CWE-863

Incorrect Authorization