Skip to main content

Vendor/product archive

cbot / cbot_core CVEs

Beta · best-effort

6 CVEs tagged to cbot / cbot_core3 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-2887

Published May 25, 2023

Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2886

Published May 25, 2023

Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation. This issue affects Chatbot: before Core: v4.0.3.4…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2885

Published May 25, 2023

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM). This issue affects C…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2884

Published May 25, 2023

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2883

Published May 25, 2023

Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2882

Published May 25, 2023

Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1