PT-2026-4814 · Unknown · Livehelperchat
CVE-2026-0483
·
Publicado
2026-01-26
·
Atualizado
2026-01-28
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Live Helper Chat versions prior to 4.72
Description
A stored Cross-Site Scripting (XSS) issue exists in the PDF file upload functionality. An attacker can upload a malicious PDF file containing an XSS payload. When a user downloads and opens the file through a link generated by the application, the payload is executed in the user’s context, allowing arbitrary JavaScript code to run locally.
Recommendations
Update Live Helper Chat to version 4.72 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Livehelperchat