What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TOCHAT.BE allows Stored XSS.This issue affects TOCHAT.BE: from n/a through 1.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TOCHAT.BE allows Stored XSS.This issue affects TOCHAT.BE: from n/a through 1.3.0.
Explanation of Vulnerability in Simple Terms
TOCHAT.BE versions up to 1.3.0 contain a cross-site scripting vulnerability that allows attackers to inject malicious scripts without authentication. The vulnerability affects the integrity and availability of the application. No user interaction is required for exploitation, making it a network-accessible risk.
What an attacker can do
Inject malicious scripts that alter page content or disrupt service availability.
Potential impact on your site
Visitors may see altered content or experience service disruptions if TOCHAT.BE is integrated into your site.
Conditions required to exploit
Network access to TOCHAT.BE; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities