CVE-2021-44162

Publication date

2021-12-20 03:10:21

Family

twcert

State

PUBLISHED

Description

Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.