Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h66r-8738-fm4g

Опубликовано: 21 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

EPSS

Процентиль: 62%
0.00423
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

EPSS

Процентиль: 62%
0.00423
Низкий

Дефекты

CWE-22