Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
The vulnerability has been fixed by the Oct8ne team in the latest version.
Workaround
No workaround given by the vendor.
Thu, 30 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:oct8ne:chatbot:2.3:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 22 Oct 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user, through /Data/SaveInteractions. |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oct8ne
Oct8ne chatbot |
|
| Vendors & Products |
Oct8ne
Oct8ne chatbot |
Wed, 15 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-22T08:22:09.442Z
Reserved: 2025-09-23T10:16:04.541Z
Link: CVE-2025-10869
Updated: 2025-10-15T13:08:46.326Z
Status : Analyzed
Published: 2025-10-15T13:16:00.870
Modified: 2025-10-30T16:29:49.613
Link: CVE-2025-10869
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:41:03Z