Description
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from Chain Sea Information Integration Co., Ltd
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31012 | Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5397-b1f40-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T23:42:02.518Z
Reserved: 2021-11-23T00:00:00.000Z
Link: CVE-2021-44162
No data.
Status : Modified
Published: 2021-12-20T03:15:06.713
Modified: 2024-11-21T06:30:28.513
Link: CVE-2021-44162
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD