Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Chinasea Subscribe
Filtered by product Qb Smart Service Robot
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44163 1 Chinasea 1 Qb Smart Service Robot 2021-12-27 4.3 MEDIUM 6.1 MEDIUM
Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.
CVE-2021-44162 1 Chinasea 1 Qb Smart Service Robot 2021-12-27 5.0 MEDIUM 7.5 HIGH
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
CVE-2021-44164 1 Chinasea 1 Qb Smart Service Robot 2021-12-27 7.5 HIGH 9.8 CRITICAL
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.