Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-12-20T03:10:21.588678Z

Updated: 2024-09-16T23:42:02.518Z

Reserved: 2021-11-23T00:00:00

Link: CVE-2021-44162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-20T03:15:06.713

Modified: 2021-12-27T17:02:37.997

Link: CVE-2021-44162

cve-icon Redhat

No data.