Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ai3
Ai3 qbibot |
|
CPEs | cpe:2.3:a:ai3:qbibot:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ai3
Ai3 qbibot |
Wed, 07 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-08-02T10:31:38.785Z
Updated: 2024-08-07T16:14:18.960Z
Reserved: 2024-07-29T04:10:59.597Z
Link: CVE-2024-7204
Vulnrichment
Updated: 2024-08-07T16:14:11.679Z
NVD
Status : Analyzed
Published: 2024-08-02T11:16:43.987
Modified: 2024-09-11T14:23:45.127
Link: CVE-2024-7204
Redhat
No data.