What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in aitool AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot ai-seo-translator allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot: from n/a through <= 1.6.2.
Explanation of Vulnerability in Simple Terms
02Summary
The AIKCT Engine Chatbot contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unwanted actions on behalf of a logged-in user. An attacker can craft a malicious link or webpage that, when visited by a user, triggers unintended state-changing operations. The vulnerability affects versions up to 1.6.2 and requires user interaction to exploit.
What an attacker can do
03Attacker Capabilities
Perform unwanted actions (like changing settings or submitting forms) on behalf of a logged-in user without their knowledge.
Potential impact on your site
04Site Impact
Users' accounts can be manipulated to perform unintended actions if they visit malicious sites while logged in to the chatbot.
Conditions required to exploit
05Prerequisites
A logged-in user must visit an attacker-controlled webpage or click a malicious link while authenticated to the chatbot.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 28, 2026
Record updated