PT-2024-21926 · Unknown · Livehelperchat

Hebing123

·

Published

2024-02-28

·

Updated

2024-07-03

·

CVE-2024-27516

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions livehelperchat versions prior to 4.34
Description A Server-Side Template Injection (SSTI) issue allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc web/modules/lhfaq/faqweight.php.
Recommendations For versions prior to 4.34, update to version 4.34 or later to resolve the issue. As a temporary workaround, consider restricting access to the lhc web/modules/lhfaq/faqweight.php module until a patch is available. Avoid using the search parameter in the affected module until the issue is resolved.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-27516
GHSA-V4CP-2Q7V-HG9Q

Affected Products

Livehelperchat