CVE-2024-27565: SSRF
Published Mar 5, 2024
·Updated
A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.
Affected Software
2 affected components
ChatGPT wechat-personal
dirk1983 Chatgpt-wechat-personal=2023-03-29
Event History
Mar 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27565?
CVE-2024-27565 is classified with a high severity due to its capability to exploit server-side request forgery vulnerabilities.
2
How do I fix CVE-2024-27565?
To fix CVE-2024-27565, update your ChatGPT-wechat-personal software to the latest version that addresses this SSRF vulnerability.
3
What is affected by CVE-2024-27565?
CVE-2024-27565 affects the weixin.php file in the ChatGPT-wechat-personal application version 2023-03-29.
4
What type of vulnerability is CVE-2024-27565?
CVE-2024-27565 is a Server-Side Request Forgery (SSRF) vulnerability.
5
Who is the vendor associated with CVE-2024-27565?
The vendor associated with CVE-2024-27565 is Dirk1983, the creator of the ChatGPT-wechat-personal application.