← back
CVE-2024-8400

Stored XSS in gaizhenbiao/chuanhuchatgpt

CVSS 5.4 MEDIUMEPSS 0.4%CWE-79
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.4%KEV nãoPoC Patch
Lifecycle
20 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the context of the user's browser.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →