CBOT Chatbot是CBOT公司的一个人工智能驱动的实时聊天解决方案。 CBOT Chatbot Core v4.0.3.4 之前版本、 Panel v4.0.3.7之前版本存在安全漏洞,该漏洞源于WebSockets中缺少来源验证,允许通过应用程序 API 进行内容欺骗。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-2887 | 9.8 CRITICAL | User Authentication Bypass in CBOT's Chatbot |
| CVE-2023-2884 | 9.8 CRITICAL | Insecure Randomness in CBOT's Chatbot |
| CVE-2023-2882 | 9.8 CRITICAL | Privilege Escalation in CBOT's Chatbot |
| CVE-2023-2883 | 8.8 HIGH | IDOR in CBOT's Chatbot |
| CVE-2023-2885 | 8.1 HIGH | Channel Accessible by Non-Endpoint in CBOT's Chatbot |
No comments yet