Chain Sea Information Integration Co., Ltd ai chatbot system - Path Traversal
Description
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Path traversal in Chain Sea ai chatbot's logo download function allows unauthenticated remote attackers to download arbitrary system files.
Vulnerability
The Chain Sea ai chatbot system (text customer service) contains a path traversal vulnerability in its file download function for logo files. The function fails to properly filter special characters in URL parameters, allowing directory traversal sequences. Affected versions are not explicitly listed; contact vendor for details. [1]
Exploitation
An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the logo download endpoint with path traversal sequences (e.g., ../) in the URL parameter. No authentication or user interaction is required. [1]
Impact
Successful exploitation allows the attacker to download arbitrary system files from the server, leading to information disclosure of sensitive data. The CVSS score is 7.5 (High) with confidentiality impact High, integrity and availability None. [1]
Mitigation
The vendor (Chain Sea / 程曦資訊整合) has not released a specific fixed version publicly. The recommended mitigation is to contact the vendor for a version update. No workaround is provided. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Chain Sea Information Integration Co., Ltd/ai chatbot systemv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-5397-b1f40-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.