Vulnerabilities > CVE-2021-44162 - Unspecified vulnerability in Chinasea QB Smart Service Robot
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |