A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/dirk1983/chatgpt/issues/114 |
History
Tue, 06 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-918 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-05T00:00:00
Updated: 2024-08-06T14:14:29.938Z
Reserved: 2024-02-26T00:00:00
Link: CVE-2024-27564
Vulnrichment
Updated: 2024-08-02T00:34:52.359Z
NVD
Status : Awaiting Analysis
Published: 2024-03-05T17:15:06.997
Modified: 2024-08-06T15:35:10.030
Link: CVE-2024-27564
Redhat
No data.