Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-10833

eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.1%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2024-10833
  • Dbgpt » Db-Gpt » Version: 0.6.0
    cpe:2.3:a:dbgpt:db-gpt:0.6.0


Contact Us

Shodan ® - All rights reserved