PT-2020-15615 · Michael Design · Ichat Realtime Php Live Support System

Published

2020-08-27

·

Updated

2020-09-02

·

CVE-2020-23983

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Michael-design iChat Realtime PHP Live Support System version 1.6
Description The issue is related to persistent Cross-site Scripting. This occurs via chat, specifically through text-field tags.
Recommendations For Michael-design iChat Realtime PHP Live Support System version 1.6, consider disabling the chat feature until a patch is available to prevent exploitation. Restrict access to the text-field tags in the chat functionality to minimize the risk of Cross-site Scripting attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23983

Affected Products

Ichat Realtime Php Live Support System