PT-2020-20740 · Livezilla · Livezilla Live Chat

Ari034

+1

·

Published

2020-03-09

·

Updated

2020-03-10

·

CVE-2020-9758

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LiveZilla Live Chat version 8.0.1.3
Description A blind JavaScript injection issue exists in the name parameter of the chat.php file. This can lead to a privilege escalation from unauthenticated to user-level access, resulting in full account takeover. The issue allows the fetching of helpdesk employees' usernames and passwords, which are stored in the database, due to a stored XSS vulnerability. This affects the mobile/chat URI via the lgn and psswrd parameters.
Recommendations For LiveZilla Live Chat version 8.0.1.3, consider disabling the name parameter in the chat.php file as a temporary workaround until a patch is available. Restrict access to the mobile/chat URI to minimize the risk of exploitation. Avoid using the lgn and psswrd parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9758

Affected Products

Livezilla Live Chat