← Retour aux CVEs
CVE-2021-44164
CRITICAL9.8
Description
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie12/20/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
chinasea:qb_smart_service_robot
Faiblesses (CWE)
CWE-434
References
https://www.twcert.org.tw/tw/cp-132-5400-c31d1-1.html(twcert@cert.org.tw)
https://www.twcert.org.tw/tw/cp-132-5400-c31d1-1.html(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.