OSV 1.4.0 · unreviewed · 修改于 2021-12-21 08:00
发布时间
2021-12-21 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-20 11:15
源文件
advisories/unreviewed/2021/12/GHSA-h66r-8738-fm4g/GHSA-h66r-8738-fm4g.json
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
该公告没有提供结构化的受影响软件包信息。