Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qp2-9c8g-2g8x

Опубликовано: 02 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.

Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.

EPSS

Процентиль: 55%
0.00321
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.

EPSS

Процентиль: 55%
0.00321
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79