Description
ChatGPT-Next-Web suffers from a combined SSRF and XSS vulnerability allowing full-read capabilities and cross-site scripting through specially crafted HTTP requests.
Remediation
Restrict access to ChatGPT-Next-Web from the Internet and update to a version with the vulnerability patched.
References
Related Vulnerabilities
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2023-0216)
WebLogic Observable Discrepancy Vulnerability (CVE-2019-3740)
Moodle Missing Authorization Vulnerability (CVE-2024-48898)
Play Framework Inadequate Encryption Strength Vulnerability (CVE-2019-17598)
Oracle Database Server CVE-2006-1876 Vulnerability (CVE-2006-1876)