PT-2024-21926 · Unknown · Livehelperchat

·

CVE-2024-27516

·

Published

2024-02-28

·

Updated

2024-07-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions livehelperchat versions prior to 4.34
Description A Server-Side Template Injection (SSTI) issue allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc web/modules/lhfaq/faqweight.php.
Recommendations For versions prior to 4.34, update to version 4.34 or later to resolve the issue. As a temporary workaround, consider restricting access to the lhc web/modules/lhfaq/faqweight.php module until a patch is available. Avoid using the search parameter in the affected module until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-27516
GHSA-V4CP-2Q7V-HG9Q

Affected Products

Livehelperchat