CVE-2024-48396
CVE-2024-48396
Título es
CVE-2024-48396
Vie, 25/10/2024 – 21:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-48396
Descripción en
AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.
25/10/2024
25/10/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off
