Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Oct8ne Oct8ne chatbot | |
| Vendors & Products | Oct8ne Oct8ne chatbot | 
Wed, 15 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-15T13:08:50.430Z
Reserved: 2025-09-23T10:16:04.541Z
Link: CVE-2025-10869
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-15T13:08:46.326Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-15T13:16:00.870
Modified: 2025-10-16T15:28:59.610
Link: CVE-2025-10869
 Redhat
                        Redhat
                    No data.