01642 06 11 11 Arrange Call

Server-Side Request Forgery (SSRF) Vulnerability in ChatGPT's pictureproxy.php

CVE-2024-27564 · MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CVE-2024-27564

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.

Learn more about our Web Application Penetration Testing UK.