Filtered by vendor Quantumcloud
Subscriptions
Filtered by product Ai Chatbot
Subscriptions
Total
22 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-1651 | 1 Quantumcloud | 1 Ai Chatbot | 2024-11-21 | 5.4 Medium |
The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS | ||||
CVE-2023-1011 | 1 Quantumcloud | 1 Ai Chatbot | 2024-11-21 | 6.1 Medium |
The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them. |