PT-2025-43058 · Unknown · Oct8Ne Chatbot

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-11952

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oct8ne Chatbot version 2.3
Description A stored cross-site scripting (XSS) issue exists in Oct8ne Chatbot version 2.3. This allows an attacker to execute JavaScript code in a victim’s browser by injecting a malicious payload through the creation of a transcript sent by email. Exploitation can lead to the theft of sensitive user data, such as session cookies, or actions performed on behalf of the user. The attack vector involves the /Records/SendSummaryMail API endpoint.
Recommendations Update Oct8ne Chatbot to a newer version that addresses this issue. As a temporary workaround, sanitize all user-supplied input before it is stored or displayed to prevent the injection of malicious scripts. Restrict access to the /Records/SendSummaryMail endpoint to authorized users only.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11952

Affected Products

Oct8Ne Chatbot