CVE-2024-7714: AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls

CVE-2024-7714: AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls-渗透云记 - 专注于网络安全与技术分享
CVE-2024-7714: AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-7714: AI Assistant with ChatGPT by AYS <= 2.0.9 – Unauthenticated AJAX Calls

漏洞描述

The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: ays_chatgpt_disconnect, ays_chatgpt_connect, and ays_chatgpt_save_feedback

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享