PT-2024-33095 · Unknown · Aiml Chatbot

Published

2024-10-25

·

Updated

2024-10-30

·

CVE-2024-48396

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AIML Chatbot versions prior to 2.0
Description The issue is related to Cross Site Scripting (XSS), where attackers can inject malicious HTML or JavaScript code through the message input field. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.
Recommendations For versions prior to 2.0, update to version 2.0 to resolve the issue. As a temporary workaround, consider restricting user input in the message field to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-48396

Affected Products

Aiml Chatbot