NextChat v2.12.3 suffers from a Server-Side Request Forgery (SSRF) and Cross-Site Scripting vulnerability due to a lack of validation of the GET parameter on the WebDav API endpoint.
id: CVE-2024-38514
info:
name: NextChat - Server-Side Request Forgery
author: DhiyaneshDk
sev
...