#Access To ChatGPT While In Capacity For Free Without ChatGPT Plus

3 messages · Page 1 of 1 (latest)

tulip salmon
#

Description:
When a user has a ChatGPT Plus subscription, they can access the site during high demands with the login using the email function. However, it has been discovered that unauthorised users who do not have a valid ChatGPT Plus subscription can also access the subscriber email login page (Accounts with the option to purchase an upgrade to chatgpt plus). This is a security concern as it allows unauthorised access. The bug report outlines the steps to reproduce the issue and possible solutions.
Steps to reproduce it:

  1. Have the Upgrade to Plus option in the dashboard
  2. Press on upgrade to plus with a VPN with the location set to LONDON (Not sure if this step is required, but I will put this in)
  3. An error should occur
  4. It works with incognito mode and non-incognito mode, too, but I will open a new incognito mode
  5. Go to chat.openai.com
  6. Type the email and press send
  7. An email should appear in the inbox
  8. The authentication link works, and you are in.
  9. Tested with accounts with no upgrade option, does not work
    How to resolve:
  10. Ban VPN usage to access ChatGPT
  11. Ping the payment provider for every request to check active subscription = true
  12. Keep a list of active subscription emails in a database that updates every 5 minutes (less than 5 minutes will waste resources), and each request should be compared with the list.
    ————-
    PS: The bug has already been reported using chat support function. Don’t know if the dev will see it or not, so I came here. If this helps, I don’t mind free ChatGPT plus as a reward. (:
blazing falconBOT
tulip salmon
#

^ What can I do with that?