Description
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
Published: 2026-08-24
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote cross‑site scripting
Action: Patch promptly
AI Analysis

Impact

A remote cross‑site scripting flaw exists in the Support chatbot of Nopaperforms Niaa‑Chatbot. The flaw allows an attacker to input an arbitrary email address that is not validated, enabling the injection and execution of any web script or HTML. Successful exploitation can lead to theft of user credentials, session hijacking, or the delivery of malicious content in the victim’s browser, thereby compromising confidentiality and integrity of the application and its users.

Affected Systems

The vulnerability affects releases of Nopaperforms Niaa‑Chatbot dated on or before 2022‑05‑17. The chat support component processes an "Enter email" field from users without proper sanitization, making earlier versions susceptible. No product version is listed as patched in the supplied data, indicating that at the time of disclosure the affected component lacked a fix.

Risk and Exploitability

The CVSS score of 6.1 marks it as medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not currently included in the CISA KEV catalog. Attackers can reach the vulnerable parameter via the normal web interface, without requiring elevated privileges or local access.

Generated by OpenCVE AI on August 28, 2026 at 06:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Nopaperforms Niaa‑Chatbot release that contains the XSS fix; if no such patch is available, proceed to the next steps.
  • Sanitize or escape user input from the Enter email field before rendering it in the chat interface to neutralize injected scripts.
  • Restrict chatbot access to authenticated or trusted users, or disable the component entirely until the vulnerability is resolved.

Generated by OpenCVE AI on August 28, 2026 at 06:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-54100
History

Fri, 28 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unvalidated Email Input in Nopaperforms Niaa‑Chatbot

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Mon, 24 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unvalidated Email Input in Nopaperforms Niaa‑Chatbot
Weaknesses CWE-79

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T19:09:20.010Z

Reserved: 2022-05-18T00:00:00.000Z

Link: CVE-2022-30983

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-24T21:16:45.793

Modified: 2026-09-09T16:04:24.933

Link: CVE-2022-30983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')