Home » Database

AVID-2026-R0925

Description

Chain Sea Information Integration Co., Ltd ai chatbot system - Reflected XSS (CVE-2021-44163)

Details

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.

Reason for inclusion in AVID: The CVE describes a reflected XSS vulnerability in the Chain Sea AI chatbot backend. This is a software vulnerability within an AI-related system component that could be used in building/serving AI chat capabilities. It affects the software stack rather than hardware/firmware, and it relates to security/safety risks (XSS). The report provides clear signals (CVE reference, description, impact) to support classification in the AI software supply chain context.

References

Affected or Relevant Artifacts

  • Developer: Chain Sea Information Integration Co., Ltd
  • Deployer: Chain Sea Information Integration Co., Ltd
  • Artifact Details:
TypeName
Systemai chatbot system

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score6.1
Base Severity🟠 Medium
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality Impact🟢 Low
Integrity Impact🟢 Low
Availability ImpactNONE

CWE

IDDescription
CWE-79CWE-79 Cross-site Scripting (XSS)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2021-12-20
  • Version: 0.3.3
  • AVID Entry