The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/c88b22ba-4fc2-49ad-a457-224157521bad | Exploit |
Configurations
History
11 May 2023, 18:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
References | (MISC) https://wpscan.com/vulnerability/c88b22ba-4fc2-49ad-a457-224157521bad - Exploit |
08 May 2023, 14:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-08 14:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-1651
Mitre link : CVE-2023-1651
CVE.ORG link : CVE-2023-1651
JSON object : View
Products Affected
quantumcloud
- ai_chatbot
CWE
No CWE.