Junglewise Threat Intelligence

CVE-2024-6035: PYSEC-2024-61 - A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attack

CVE-2024-6035 · Severity: low · CVSS 3.1 · Published 2024-07-11

Technologies: chuanhuchatgpt (PyPI). Vendors: PyPI.

Executive brief

A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history file. When a victim uploads this file, the malicious script is executed in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.

Affected products

  • PyPI chuanhuchatgpt

Related threats