Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48172 | Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack. |
Fixes
Solution
Update to version 8.0.9.02 or later, or install the patch.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ai3
Ai3 qbibot |
|
| CPEs | cpe:2.3:a:ai3:qbibot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ai3
Ai3 qbibot |
Wed, 07 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-07T16:14:18.960Z
Reserved: 2024-07-29T04:10:59.597Z
Link: CVE-2024-7204
Updated: 2024-08-07T16:14:11.679Z
Status : Analyzed
Published: 2024-08-02T11:16:43.987
Modified: 2024-09-11T14:23:45.127
Link: CVE-2024-7204
No data.
OpenCVE Enrichment
No data.
EUVD