VulnerabilityAnalyzed
CVE-2025-2334
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5.
MEDIUM 5.3EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the argument chatListId leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-284
- Affected
- 274056675/springboot-openai-chatgpt
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.299799Permissions Required, VDB Entry
- https://vuldb.com/?id.299799Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.505688Third Party Advisory, VDB Entry
- https://www.cnblogs.com/aibot/p/18732182Exploit, Third Party Advisory
- https://www.cnblogs.com/aibot/p/18732182Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.