CVE-2021-44164

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/12/2021
Last modified:
27/12/2021

Description

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:chinasea:qb_smart_service_robot:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools