Record summary

CVE-2024-38514 has a selected CVSS score of 7.4 (high); EIP currently links 1 Nuclei template.

Description

NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpoint` GET parameter on the WebDav API endpoint. This SSRF can be used to perform arbitrary HTTPS request from the vulnerable instance (MKCOL, PUT and GET methods supported), or to target NextChat users and make them execute arbitrary JavaScript code in their browser. This vulnerability has been patched in version 2.12.4.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 25, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 2, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 2.12.4affected
VulnCheckVersion data not supplied

Default status: unknown

CVE ListBefore 2.12.4affected

Nuclei templates

1
ProjectDiscoveryHIGHNextChat - Server-Side Request ForgeryCVSS 7.4

NextChat v2.12.3 suffers from a Server-Side Request Forgery (SSRF) and Cross-Site Scripting vulnerability due to a lack of validation of the GET parameter on the WebDav API endpoint.

Impact

Unauthenticated attackers can perform SSRF attacks to access internal services, scan internal networks, or exfiltrate sensitive information from systems that should not be accessible externally.

Remediation

Upgrade to NextChat version 2.12.4 or later that includes proper validation of the endpoint parameter.

WeaknessesCWE-918
AuthorsDhiyaneshDk
Template tagscvecve2024ssrfxsschatgptnextchatvkevvulnai
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Shodan: title:NextChat,"ChatGPT Next Web"

Source: ProjectDiscovery

References

2