Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xm2p-hxq8-xj3q

Опубликовано: 05 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.

A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.

EPSS

Процентиль: 100%
0.91497
Критический

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.8
nvd
почти 2 года назад

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.

EPSS

Процентиль: 100%
0.91497
Критический

6.5 Medium

CVSS3

Дефекты

CWE-918