Description
ChatGPT-Next-Web suffers from a combined SSRF and XSS vulnerability allowing full-read capabilities and cross-site scripting through specially crafted HTTP requests.
Remediation
Restrict access to ChatGPT-Next-Web from the Internet and update to a version with the vulnerability patched.
References
Related Vulnerabilities
MySQL CVE-2016-9840 Vulnerability (CVE-2016-9840)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50723)
WordPress Plugin WP Gravity Forms Zoho CRM Add-on Cross-Site Scripting (1.1.5)
WordPress Use of Insufficiently Random Values Vulnerability (CVE-2017-17091)