CVE-2024-9216
An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises because the username is provided via an HTTP request from the client side, rather than being read from a secure source like a cookie. This allows an attacker to pass another user's username to the get_model function, thereby gaining unauthorized access to that user's chat history.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.61%
- CWE
- CWE-304
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- gaizhenbiao gaizhenbiao/chuanhuchatgpt
Weakness type
Related vulnerabilities
- CVE-2023-54391 — Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
- CVE-2026-59564 — Authentication bypass between ZCC and client connector portal
- CVE-2026-76207 — phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-61466 — Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
- CVE-2026-67351 — Serendipity < 2.6.1 Authentication Bypass via Username Collision
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2026-57915 — Apache Kerby: Kerberos Pre-Authentication Bypass