Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv5h-978v-cqvr

Опубликовано: 21 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

EPSS

Процентиль: 86%
0.03047
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

EPSS

Процентиль: 86%
0.03047
Низкий

Дефекты

CWE-434