Skip to main content
Loading…
    CVE-2024-10901 — In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attacker — CVE Database · The Intelligence Room