CVE-2024-29090Server-Side Request Forgery in AI Engine

Severity
6.8MEDIUMNVD
EPSS
0.8%
top 26.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28

Description

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 2.3 | Impact: 4.0

Affected Packages2 packages

CVEListV5jordy_meow/ai_engine_chatgpt_chatbotn/a2.1.4
NVDmeowapps/ai_engine< 2.1.5

🔴Vulnerability Details

2
CVEList
WordPress AI Engine plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability2024-03-28
GHSA
GHSA-9xp7-754r-wj55: Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot2024-03-28
CVE-2024-29090 — Server-Side Request Forgery | cvebase