6.5
CVSSv3

CVE-2024-27564

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.91787 | KEV: Not Included
Published: 05/03/2024 Updated: 20/03/2025

Vulnerability Summary

SSRF Vulnerability via Crafted URL Injection in ChatGPT Pictureproxy

A Server-Side Request Forgery (SSRF) vulnerability exists in ChatGPT commit f9f4bbc through the pictureproxy.php file. Attackers can exploit this by injecting crafted URLs into the url parameter, forcing the application to make arbitrary requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dirk1983 chatgpt f9f4bbc

dirk1983 mm1.ltd source code

dirk1983 chatgpt 2023-05-23

Vendor Advisories

Check Point Reference: CPAI-2024-0873 Date Published: 14 Oct 2024 Severity: Medium ...

Github Repositories