CVE-2025-10869

⚪ Do wiadomości

Wstrzyknięcie XSS w Oct8ne Chatbot umożliwia kradzież danych użytkowników.

CVSS
6.1
EPSS
0.2%
Exploit
none
Vendor
oct8ne
Opis źródłowy (NVD)

Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user, through /Data/SaveInteractions.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-15 13:16:00 UTC
Ostatnia modyfikacja (NVD)2026-10-08 12:10:00 UTC
Referencje