CVE-2024-27564 is a Server-Side Request Forgery (SSRF) vulnerability found in the pictureproxy.php component of the dirk1983 mm1.ltd source code, specifically affecting the dirk1983 chatgpt product. This medium-severity vulnerability, with a CVSS score of 6.5, allows unauthenticated attackers to make arbitrary requests from the server by manipulating the 'url' parameter, potentially leading to information disclosure or unauthorized actions. While not yet listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 99/100 indicate a significant likelihood of exploitation. Exploit intelligence shows a Nuclei template for this vulnerability, and it has garnered community discussion and media coverage, including reports of its exploitation against US government organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2023-05-23CPE matchmatch criteria | cpe:2.3:a:dirk1983:chatgpt:2023-05-23:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.