CVE-2024-10902 | eosphoros-ai db-gpt up to 0.6.0 Web API upload file inclusion
A vulnerability was found in eosphoros-ai db-gpt up to 0.6.0 and classified as critical. Affected by this issue is some unknown functionality of the file /v1/personal/agent/upload of the component Web API. The manipulation leads to file inclusion.
This vulnerability is handled as CVE-2024-10902. The attack may be launched remotely. There is no exploit available.