GHSA-8wcc-f2vq-h4gx
Dashboard / Vulnerabilities / GHSA-8wcc-f2vq-h4gx
Summary: Cross-site Scripting in livehelperchat
Details: Stored XSS is found in Settings>Live help configuration>Personal Theme>static content. Under the NAME field put a payload {{constructor.constructor('alert(1)')()}} while creating content, and you will see that the input gets stored, and every time the user visits, the payload gets executed.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-0370, https://github.com/livehelperchat/livehelperchat/commit/9f5bc33c943349bd765b991db0b7f6b6ef05cfdb, https://github.com/livehelperchat/livehelperchat, https://huntr.dev/bounties/fbe4b376-57ce-42cd-a9a9-049c4099b3ca
Affected packages
Package
Name: remdex/livehelperchat
Purl: pkg:composer/remdex/livehelperchat
Affected ranges
Type: ECOSYSTEM
Events:
