在 HAVELSAN Inc. Sef - AI Chatbot Platform 中存在一个“SQL命令中特殊元素未正确处理”(即 SQL 注入)的漏洞,导致系统容易受到 SQL 注入攻击。 该问题影响 HAVELSAN Inc. Sef - AI Chatbot Platform 的 2.1 之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HAVELSAN Inc. | Sef - AI Chatbot Platform | < 2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HAVELSAN Inc. | Sef - AI Chatbot Platform | 0 ~ 2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80443 | 7.4 HIGH | Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Pla |
| CVE-2026-80337 | 5.3 MEDIUM | Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform |
| CVE-2026-80464 | 4.9 MEDIUM | API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform |
No comments yet