PT-2025-43058 · Unknown · Oct8Ne Chatbot
Published
2025-10-22
·
Updated
2025-10-22
·
CVE-2025-11952
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Oct8ne Chatbot version 2.3
Description
A stored cross-site scripting (XSS) issue exists in Oct8ne Chatbot version 2.3. This allows an attacker to execute JavaScript code in a victim’s browser by injecting a malicious payload through the creation of a transcript sent by email. Exploitation can lead to the theft of sensitive user data, such as session cookies, or actions performed on behalf of the user. The attack vector involves the
/Records/SendSummaryMail API endpoint.Recommendations
Update Oct8ne Chatbot to a newer version that addresses this issue. As a temporary workaround, sanitize all user-supplied input before it is stored or displayed to prevent the injection of malicious scripts. Restrict access to the
/Records/SendSummaryMail endpoint to authorized users only.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oct8Ne Chatbot