Springboot OpenAI ChatGPT Hard-Coded Credentials Vulnerability

Vulnerability

A critical vulnerability has been identified in the Springboot OpenAI ChatGPT project, specifically in the commit e84f6f5. The issue arises from hard-coded credentials in the file OpenController.java, located in the chatgpt-boot module. This vulnerability allows remote exploitation without requiring authentication, potentially leading to unauthorized access with administrative privileges.

Impact

Exploitation of this vulnerability allows for unauthorized access to administrative functions, bypassing normal authentication mechanisms.

Reproduction

To reproduce this vulnerability, use the hard-coded phone number '13800138000' and the code '888888' to log into the system. This will grant access to administrator privileges.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.