PT-2024-10837 · Unknown · Awesomestcode Livebot

Awesomestcode Livebot

·

Published

2024-03-25

·

Updated

2024-05-17

·

CVE-2020-36826

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions AwesomestCode LiveBot (affected versions not specified)
Description A vulnerability was found in AwesomestCode LiveBot, classified as problematic, affecting the function parseSend of the file js/parseMessage.js. This leads to cross-site scripting and can be launched remotely. It is recommended to verify all input to prevent attacks.
Recommendations As a temporary workaround, consider disabling the parseSend function until a patch is available. Upgrade to version 0.1 to address this issue. Restrict access to the js/parseMessage.js file to minimize the risk of exploitation. Verify all input to prevent attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-36826

Affected Products

Awesomestcode Livebot