VYPR

CWE-1057

Data Access Operations Outside of Expected Data Manager Component

BaseIncomplete

Description

The product uses a dedicated, central data manager component as required by design, but it contains code that performs data-access operations that do not use this data manager.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1)

  • CVE-2024-8143MedOct 29, 2024
    risk 0.00cvss 4.3epss 0.00

    In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By…