Zalo · Zalo Official Live Chat · CVE-2025-46498
**Name of the Vulnerable Software and Affected Versions**
Zalo Official Live Chat versions 1.0.0 and earlier
**Description**
The issue is a Cross-Site Request Forgery (CSRF) vulnerability, which allows for Cross Site Request Forgery. This means an attacker can trick a user into performing unintended actions on a web application that the user is authenticated to.
**Recommendations**
For Zalo Official Live Chat versions 1.0.0 and earlier, as a temporary workaround, consider implementing proper CSRF token validation to prevent unauthorized requests.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.