A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can contain malicious scripts, leading to stored Cross-Site Scripting (XSS) attacks. Through stored XSS, an attacker can steal information about the victim and perform any action on their behalf.
CVE ID: CVE-2024-10819
CVSS Base Severity: HIGH
CVSS Base Score: 7.1
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Vendor: binary-husky
Product: binary-husky/gpt_academic
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.74% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)