Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oct8ne
Oct8ne chatbot |
|
| Vendors & Products |
Oct8ne
Oct8ne chatbot |
Wed, 15 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-15T13:08:50.430Z
Reserved: 2025-09-23T10:16:04.541Z
Link: CVE-2025-10869
Updated: 2025-10-15T13:08:46.326Z
Status : Awaiting Analysis
Published: 2025-10-15T13:16:00.870
Modified: 2025-10-16T15:28:59.610
Link: CVE-2025-10869
No data.