pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.
History

Thu, 20 Mar 2025 04:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dirk1983:chatgpt:f9f4bbc:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 04:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Thu, 20 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter. pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.
References

Tue, 21 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dirk1983
Dirk1983 chatgpt
CPEs cpe:2.3:a:dirk1983:chatgpt:2023-05-23:*:*:*:*:*:*:*
Vendors & Products Dirk1983
Dirk1983 chatgpt

Tue, 06 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-05T00:00:00.000Z

Updated: 2025-03-20T14:28:44.751Z

Reserved: 2024-02-26T00:00:00.000Z

Link: CVE-2024-27564

cve-icon Vulnrichment

Updated: 2024-08-02T00:34:52.359Z

cve-icon NVD

Status : Modified

Published: 2024-03-05T17:15:06.997

Modified: 2025-03-20T15:15:41.543

Link: CVE-2024-27564

cve-icon Redhat

No data.