CVE-2021-44163

Publication date

2021-12-20 03:10:22

Family

twcert

State

PUBLISHED

Description

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.