PT-2026-4814 · Unknown · Livehelperchat

CVE-2026-0483

·

Publicado

2026-01-26

·

Atualizado

2026-01-28

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Live Helper Chat versions prior to 4.72
Description A stored Cross-Site Scripting (XSS) issue exists in the PDF file upload functionality. An attacker can upload a malicious PDF file containing an XSS payload. When a user downloads and opens the file through a link generated by the application, the payload is executed in the user’s context, allowing arbitrary JavaScript code to run locally.
Recommendations Update Live Helper Chat to version 4.72 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0483

Produtos afetados

Livehelperchat