PT-2020-16309 · Live Helper Chat · Livehelperchat

·

CVE-2020-26135

·

Published

2020-10-02

·

Updated

2024-03-06

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Live Helper Chat versions prior to 3.44v
Description The issue allows reflected XSS via the setsettingajax PATH INFO. This can potentially lead to malicious script execution.
Recommendations For versions prior to 3.44v, update to version 3.44v or later to resolve the issue. As a temporary workaround, consider restricting access to the setsettingajax PATH INFO to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-LIVEHELPERCHAT-2020-26135
CVE-2020-26135

Affected Products

Livehelperchat