Aller au contenu

Fiche vulnérabilité

CVE-2024-10819 : faille élevée binary-husky gpt academic (CVSS 8.8)

Description

A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can contain malicious scripts, leading to stored Cross-Site Scripting (XSS) attacks. Through stored XSS, an attacker can steal information about the victim and perform any action on their behalf.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 mars 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • binary-husky gpt academic

Références

Rechercher une autre vulnérabilité dans la base CVE