What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
Explanation of Vulnerability in Simple Terms
AI Engine: ChatGPT Chatbot versions up to 2.1.4 contain a server-side request forgery vulnerability that allows high-privilege users to make the site send HTTP requests to internal or external systems on their behalf. An attacker with admin or equivalent access can probe internal networks, access metadata services, or interact with backend systems. The scope is changed, meaning the impact extends beyond the plugin itself.
What an attacker can do
Make the site send HTTP requests to internal systems or external URLs to read sensitive data or interact with backend services.
Potential impact on your site
A compromised admin account can be used to probe your internal network, access cloud metadata, or attack other systems your site can reach.
Conditions required to exploit
Attacker must have high-privilege access (admin or equivalent role) on the site.
Key dates
External resources
Related vulnerabilities