PT-2022-13136 · Unknown · Livehelperchat
Published
2022-01-26
·
Updated
2024-03-06
·
CVE-2022-0375
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LiveHelperChat versions prior to 3.93v
Description
The issue is related to a Stored Cross-site Scripting (XSS) vulnerability. It affects the Name field in the Admin themes of System configuration, allowing for potential malicious script execution.
Recommendations
For versions prior to 3.93v, update to version 3.93v or later to resolve the issue. As a temporary workaround, consider restricting access to the Admin themes of System configuration to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Livehelperchat