PT-2022-13146 · Unknown · Remdex/Livehelperchat
Published
2022-01-27
·
Updated
2022-02-02
·
CVE-2022-0387
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
remdex/livehelperchat versions prior to 3.93v
Description
The issue is related to a Stored Cross-site Scripting (XSS) in the remdex/livehelperchat package. This occurs when a user creates a new webhook under the NAME field in the Departments groups edit section and inputs a malicious payload, such as
{{constructor.constructor('alert(1)')()}}. The payload gets stored and executed when the user edits the group name.Recommendations
For versions prior to 3.93v, update to version 3.93v or later to resolve the issue. As a temporary workaround, consider restricting access to the Departments groups edit section to minimize the risk of exploitation. Avoid using the NAME field in the webhook configuration until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remdex/Livehelperchat