Chain Sea Information Integration Co., Ltd ai chatbot system - Arbitrary File Upload
CVE-2021-44164
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 20 December 2021
What is CVE-2021-44164?
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.
Affected Version(s)
ai chatbot system 0
