Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxf3-qxfw-xchv

Опубликовано: 21 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-79