Description
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from Chain Sea Information Integration Co., Ltd
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31014 | Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5400-c31d1-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T18:59:15.351Z
Reserved: 2021-11-23T00:00:00.000Z
Link: CVE-2021-44164
No data.
Status : Modified
Published: 2021-12-20T03:15:06.827
Modified: 2024-11-21T06:30:28.797
Link: CVE-2021-44164
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD