PT-2026-41019 · Unknown · Livehelperchat
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Live Helper Chat version 4.84
Description
The REST API chat update endpoint allows a user with
lhchat/use permissions to update chats within departments they are not authorized to read. Because the endpoint accepts arbitrary chat object fields, an attacker can modify the chat hash and status to gain unauthorized access or tamper with the chat via visitor or widget paths. Additionally, this write primitive allows the modification of operation admin, which is subsequently executed as operator-side JavaScript.Recommendations
Update Live Helper Chat to a version newer than 4.84.
Restrict access to the REST API chat update endpoint for users with
lhchat/use permissions until the update is applied.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Livehelperchat