Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
Solution:
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://www.usom.gov.tr/bildirim/tr-23-0293 | third party advisory government resource |