Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Oct8ne
Oct8ne chatbot |
|
Vendors & Products |
Oct8ne
Oct8ne chatbot |
Wed, 15 Oct 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 15 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
Title | Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-10-15T12:37:53.634Z
Updated: 2025-10-15T13:08:50.430Z
Reserved: 2025-09-23T10:16:04.541Z
Link: CVE-2025-10869

Updated: 2025-10-15T13:08:46.326Z

Status : Awaiting Analysis
Published: 2025-10-15T13:16:00.870
Modified: 2025-10-16T15:28:59.610
Link: CVE-2025-10869

No data.