CVE-2024-9216
CVSS 3.0 Score 8.1 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 304
Summary
CVE-2024-9216 is a newly discovered authentication bypass vulnerability affecting the gaizhenbiao/ChuanhuChatGPT software, as revealed in commit 3856d4f. This issue permits any user to access and delete other users' chat history without proper authorization. The root cause lies in the fact that the username is obtained from client-side HTTP requests instead of secure sources like cookies. As a result, attackers can manipulate the username parameter to unlawfully invade other users' private data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.