Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6c7-m83j-8wqg

Опубликовано: 27 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing security controls and accessing sensitive data.

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing security controls and accessing sensitive data.

EPSS

Процентиль: 12%
0.0004
Низкий

7.3 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing security controls and accessing sensitive data.

EPSS

Процентиль: 12%
0.0004
Низкий

7.3 High

CVSS3

Дефекты

CWE-918