Description

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation.

INFO

Published Date :

2025-11-07T00:00:00.000Z

Last Modified :

2025-11-07T20:05:36.270Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63639 vulnerability.

No data.

CVSS Vulnerability Scoring System