{"api_version":"1","generated_at":"2026-07-23T14:53:36+00:00","cve":"CVE-2020-35852","urls":{"html":"https://cve.report/CVE-2020-35852","api":"https://cve.report/api/cve/CVE-2020-35852.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-35852","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-35852"},"summary":{"title":"CVE-2020-35852","description":"Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-02-23 01:15:00","updated_at":"2021-02-26 22:07:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md","name":"https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md","refsource":"MISC","tags":["Exploit","Mitigation","Third Party Advisory"],"title":"My_CVE_References/CVE-2020-35852.md at main · riteshgohil/My_CVE_References · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://getgist.com/chatbot-software/","name":"https://getgist.com/chatbot-software/","refsource":"MISC","tags":["Product"],"title":"Chatbot Software: #1 Rated For Sales And Marketing Teams","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://getgist.com","name":"https://getgist.com","refsource":"MISC","tags":["Product"],"title":"All-in-One Email Marketing Automation, Live Chat, & Help Desk Software","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-35852","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35852","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"35852","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"getgist","cpe5":"chatbox","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"35852","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"getgist","cpe5":"chatbox","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-35852","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://getgist.com","refsource":"MISC","name":"https://getgist.com"},{"url":"https://getgist.com/chatbot-software/","refsource":"MISC","name":"https://getgist.com/chatbot-software/"},{"refsource":"MISC","name":"https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md","url":"https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md"}]}},"nvd":{"publishedDate":"2021-02-23 01:15:00","lastModifiedDate":"2021-02-26 22:07:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:getgist:chatbox:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"35852","Ordinal":"195795","Title":"CVE-2020-35852","CVE":"CVE-2020-35852","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"35852","Ordinal":"1","NoteData":"Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"35852","Ordinal":"2","NoteData":"2021-02-22","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"35852","Ordinal":"3","NoteData":"2021-02-22","Type":"Other","Title":"Modified"}]}}}