Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Chain Sea Information Integration Co., Ltd ai chatbot system - Path Traversal
Vulnerability Description
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Chain Sea Ai Chatbot System 路径遍历漏洞
Vulnerability Description
Chain Sea Ai Chatbot System是中国程曦资讯(Chain Sea)公司的一个智能人工客服软件。 Chain Sea Ai Chatbot System 中存在路径遍历漏洞,该漏洞源于产品的特定文件下载功能未对URL参数中的特殊字符进行过滤。攻击者可通过该漏洞进行在不进行认证的情况下下载任意系统文件。
CVSS Information
N/A
Vulnerability Type
N/A