Unknown · Chanzhaoyu Chatgpt-Web · CVE-2023-7215
**Name of the Vulnerable Software and Affected Versions**
Chanzhaoyu chatgpt-web version 2.11.1
**Description**
A problematic issue has been found in the software, affecting some unknown processing. The manipulation of the argument `Description` with the input `<image src onerror=prompt(document.domain)>` leads to cross-site scripting. The attack may be initiated remotely.
**Recommendations**
For Chanzhaoyu chatgpt-web version 2.11.1, consider disabling the `Description` argument to prevent cross-site scripting attacks until a patch is available. Restrict access to the affected processing to minimize the risk of exploitation. Avoid using the `Description` argument with untrusted input in the affected API endpoint until the issue is resolved.