2024-12-08 03:06:42 +00:00

64 lines
2.1 KiB
JSON

{
"id": "CVE-2024-48144",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-10-24T19:15:15.510",
"lastModified": "2024-10-28T20:35:17.553",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message."
},
{
"lang": "es",
"value": "Una vulnerabilidad de inyecci\u00f3n r\u00e1pida en el cuadro de chat de Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 permite a los atacantes acceder y exfiltrar todos los datos de chat anteriores y posteriores entre el usuario y el asistente de IA a trav\u00e9s de un mensaje manipulado espec\u00edficamente."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"references": [
{
"url": "https://apps.microsoft.com/detail/9n3ff8j3d7zr?hl=en-US&gl=US",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48144",
"source": "cve@mitre.org"
}
]
}