Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-10835

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.9%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2024-10835
  • Dbgpt » Db-Gpt » Version: 0.6.0
    cpe:2.3:a:dbgpt:db-gpt:0.6.0


Contact Us

Shodan ® - All rights reserved