FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.
An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 2.0 | Primary | cve.org | 9.0 | — | — |
| 2.0 | Primary | cve.org | 9.0 | — | — |
| 2.0 | Secondary | NVD | 9.0 | 8.0 | 10.0 |
| 3.0 | Primary | cve.org | 9.9 | — | — |
| 3.0 | Primary | cve.org | 9.9 | — | — |
| 3.1 | Primary | NVD | 9.9 | 3.1 | 6.0 |
| 3.1 | Primary | cve.org | 9.9 | — | — |
| 3.1 | Primary | cve.org | 9.9 | — | — |
| 3.1 | Secondary | NVD | 9.9 | 3.1 | 6.0 |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Secondary | ENISA EUVD | 9.4 | — | — |
| 4.0 | Secondary | NVD | 8.6 | — | — |