Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Chain Sea Information Integration Co., Ltd ai chatbot system - Arbitrary File Upload
Vulnerability Description
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Chain Sea Ai Chatbot System 代码问题漏洞
Vulnerability Description
Chain Sea Ai Chatbot System是中国程曦资讯(Chain Sea)公司的一个智能人工客服软件。 Chain Sea Ai Chatbot System 存在代码问题漏洞,该漏洞源于产品文件上传功能未对URL参数中的特殊字符进行过滤。攻击者可通过该漏洞上传恶意脚本或执行任意代码,从而控制系统或终止服务。
CVSS Information
N/A
Vulnerability Type
N/A