← voltar
CVE-2024-47171

Agnai vulnerable to Relative Path Traversal in Image Upload

CVSS 4.3 MEDIUMEPSS 0.5%CWE-35
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 4.3EPSS 0.5%KEV nãoPoC Patch
Ciclo de vida
26 de set. de 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to image file uploads to unauthorized or unintended directories, including overwriting of existing images which may be used for defacement. This does not affect `agnai.chat`, installations using S3-compatible storage, or self-hosting that is not publicly exposed. Version 1.0.330 fixes this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Produtos afetados
agnaistic · agnai

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →