CVE-2020-35852 Information

Description

Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md https://getgist.com https://getgist.com/chatbot-software/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: