Junglewise Threat Intelligence

CVE-2022-30983: NoPaperForms Niaa-Chatbot cross-site scripting in email input

CVE-2022-30983 · Severity: medium · CVSS 6.1 · Published 2026-08-24

Executive brief

Niaa-Chatbot is a support chatbot widget used to provide customer service on websites. A cross-site scripting vulnerability in the email input field allows attackers to inject malicious JavaScript that executes in visitors' browsers, potentially stealing session cookies, redirecting users, or defacing content displayed to customers.

Technical details

A reflected XSS vulnerability (CWE-79) exists in the support chatbot's email input parameter due to insufficient output encoding and sanitization of user-controlled input. The vulnerability affects the email field accepted during chatbot interaction. An attacker can craft a malicious email address containing HTML/JavaScript payloads; when the chatbot processes this input, the payload executes in the context of the website hosting the chatbot. The vulnerability is triggered via a network-based attack vector requiring no authentication. A fix was expected around or after May 17, 2022, though no specific patch version is documented in the advisory.

Affected products

  • NoPaperForms Solutions Pvt. Ltd. Niaa-Chatbot through 2022-05-17

Timeline

  • 2022-05-18: disclosed: CVE assigned
  • 2022-05-17: other: Vulnerability observed in deployments through this date

References