Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-51409Unrestricted File Upload in AI Engine

Severity
9.8CRITICALNVD
CNA10.0VulnCheck10.0
EPSS
92.9%
top 0.22%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 12

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5jordy_meow/ai_engine_chatgpt_chatbotn/a1.9.98
NVDmeowapps/ai_engine< 1.9.99

🔴Vulnerability Details

3
CVEList
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability2024-04-12
GHSA
GHSA-c4qr-mpj2-hxhr: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot2024-04-12
VulnCheck
AI Engine: ChatGPT Chatbot Plugin File Upload Vulnerability2023

💥Exploits & PoCs

1
Nuclei
Jordy Meow AI Engine - Unrestricted File Upload
CVE-2023-51409 — Unrestricted File Upload in AI Engine | cvebase