ZeroHour

CVE-2024-5935

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p8
Published
()
Modified
Description

A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.

Vendors
pribai
Products
privategpt
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.