Security Advisory

CVE-2021-44163

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-12-20 03:10:22
Last updated 2024-09-16 16:43:57
Assigner twcert
State PUBLISHED

Description

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.