Lucene search

K
cvelistTwcertCVELIST:CVE-2021-44164
HistoryDec 20, 2021 - 3:10 a.m.

CVE-2021-44164 Chain Sea Information Integration Co., Ltd ai chatbot system - Arbitrary File Upload

2021-12-2003:10:24
CWE-434
twcert
www.cve.org
2
chain sea
ai chatbot
file upload
remote attacker
arbitrary code
system control
service termination
url filtering
file type validation

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.059

Percentile

93.5%

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

CNA Affected

[
  {
    "product": "ai chatbot system",
    "vendor": "Chain Sea Information Integration Co., Ltd",
    "versions": [
      {
        "status": "unknown",
        "version": "0"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.059

Percentile

93.5%

Related for CVELIST:CVE-2021-44164