PT-2020-16309 · Live Helper Chat · Livehelperchat

Rekter0

·

Published

2020-10-02

·

Updated

2024-03-06

·

CVE-2020-26135

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Live Helper Chat versions prior to 3.44v
Description The issue allows reflected XSS via the setsettingajax PATH INFO. This can potentially lead to malicious script execution.
Recommendations For versions prior to 3.44v, update to version 3.44v or later to resolve the issue. As a temporary workaround, consider restricting access to the setsettingajax PATH INFO to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-LIVEHELPERCHAT-2020-26135
CVE-2020-26135

Affected Products

Livehelperchat