Showing 2 vulnerabilities on this page for ai_chatbot_with_chatgpt

Signals CISA KEV Ransomware Nuclei
ays-pro vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CWE-862Sep 27, 20241 related artifact
CVSS7.5v3.1EPSS0.848%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

AI Chatbot with ChatGPT by AYS <= 2.0.9 - Unauthenticated OpenAI Key Disclosure

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it

CWE-201CWE-319Sep 27, 2024
CVSS7.5v3.1EPSS0.305%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX