ZeroHour

CVE-2021-44164

CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

Vendors
chinasea
Products
qb smart service robot
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.