Ai3 QbiBot Under Fire for Poor Input Filtering, Leaving Users Vulnerable to XSS Attacks
CVE-2024-7204

6.1MEDIUM

Key Information:

Vendor

Ai3

Status
Vendor
CVE Published:
2 August 2024

What is CVE-2024-7204?

Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.