What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
Explanation of Vulnerability in Simple Terms
The AI Engine: ChatGPT Chatbot plugin contains a server-side request forgery vulnerability that allows authenticated users to make the site send HTTP requests to internal or external systems on the attacker's behalf. The vulnerability requires low-level authentication and high attack complexity. Impact is limited to confidentiality and integrity of data accessible through those requests.
What an attacker can do
Make the site send HTTP requests to internal systems or external URLs under the site's identity.
Potential impact on your site
Authenticated attackers can probe internal networks, access internal services, or trigger actions on external systems via your site.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities