CVE-2024-11030

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.
Configurations

No configuration.

History

20 Mar 2025, 14:15

Type Values Removed Values Added
References () https://huntr.com/bounties/729d9928-c28a-40fd-8a86-bb4ca2984bba - () https://huntr.com/bounties/729d9928-c28a-40fd-8a86-bb4ca2984bba -

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-03-20 14:15


NVD link : CVE-2024-11030

Mitre link : CVE-2024-11030

CVE.ORG link : CVE-2024-11030


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)