CVE-2024-11030
CVSS 3.0 Score 7.7 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 918
Summary
CVE-2024-11030 is a Server-Side Request Forgery (SSRF) vulnerability affecting GPT Academic version 3.83. The issue arises from the HotReload plugin function, which utilizes the API call crazy_utils.get_files_from_everything() without appropriate sanitization. This weakness enables attackers to manipulate the request and abuse the victim's Gradio Web server credentials, allowing unauthorized access to web resources.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.