chatbot

1 article
sort: new top best
clear filter
0 6/10

An enterprise chatbot exposed an unauthenticated legacy WebSocket endpoint that accepted full bidirectional messages using only a conversation UUID, allowing attackers to hijack sessions, impersonate users, and exfiltrate sensitive chat data with minimal effort.

un1tycyb3r
un1tycyb3r.com · bugbountydaily · 4 days ago · details