Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://getgist.com | product |
https://getgist.com/chatbot-software/ | product |
https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md | mitigation third party advisory exploit |