Back

MEDIUM

Ai3 QbiBot - Stored XSS

Published Aug 2, 2024

Description

Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.

Affected products

Remediation

Vendor solution

Update to version 8.0.9.02 or later, or install the patch.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Aug 2, 2024
Updated Aug 7, 2024
Reserved Jul 29, 2024
CISA Vulnrichment
Updated Aug 7, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a