CVE-2023-7215 LOW

CVE-2023-7215: Chanzhaoyu chatgpt-web cross site scripting

Vendor Chanzhaoyu
Product chatgpt-web
Weakness CWE-79 · XSS
Published January 8, 2024
Last update June 3, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affects some unknown processing. The manipulation of the argument Description with the input <image src onerror=prompt(document.domain)> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249779.

Key dates

02Disclosure timeline

January 8, 2024 CVE published
June 3, 2025 Record updated