Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
The vulnerability has been fixed by the Oct8ne team in the latest version.
Workaround
No workaround given by the vendor.
Fri, 31 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:oct8ne:chatbot:2.3:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oct8ne
Oct8ne chatbot |
|
| Vendors & Products |
Oct8ne
Oct8ne chatbot |
Wed, 22 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Oct 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user, through /Records/SendSummaryMail. | |
| Title | Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-23T09:04:39.602Z
Reserved: 2025-10-20T09:19:23.658Z
Link: CVE-2025-11952
Updated: 2025-10-22T13:26:04.108Z
Status : Analyzed
Published: 2025-10-22T09:15:36.217
Modified: 2025-10-31T14:47:55.680
Link: CVE-2025-11952
No data.
OpenCVE Enrichment
Updated: 2025-10-23T10:07:51Z