CVE-2024-6035
- Reference to the description:
- Description:
- A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history file. When a victim uploads this file, the malicious script is executed in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
- Last updated date:
- 07/15/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 07/12/2024
- Reference url to background
https://huntr.com/bounties/e4e8da71-53a9-4540-8d70-6b670b076987