Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mido0X0X

#43934of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2024-15235
6.1
2024-01-07
Unknown · Chanzhaoyu Chatgpt-Web · CVE-2023-7215
**Name of the Vulnerable Software and Affected Versions** Chanzhaoyu chatgpt-web version 2.11.1 **Description** A problematic issue has been found in the software, affecting some unknown processing. The manipulation of the argument `Description` with the input `<image src onerror=prompt(document.domain)>` leads to cross-site scripting. The attack may be initiated remotely. **Recommendations** For Chanzhaoyu chatgpt-web version 2.11.1, consider disabling the `Description` argument to prevent cross-site scripting attacks until a patch is available. Restrict access to the affected processing to minimize the risk of exploitation. Avoid using the `Description` argument with untrusted input in the affected API endpoint until the issue is resolved.