Lucene search

K
cve[email protected]CVE-2023-5254
HistoryOct 19, 2023 - 6:15 a.m.

CVE-2023-5254

2023-10-1906:15:12
web.nvd.nist.gov
23
chatbot
wordpress
cve-2023-5254
information exposure
security vulnerability

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users.

Affected configurations

Vulners
NVD
Node
quantumcloudai_chatbotRange4.8.9
VendorProductVersionCPE
quantumcloudai_chatbot*cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "quantumcloud",
    "product": "AI ChatBot",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "4.8.9",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%

Related for CVE-2023-5254