GHSA-w4hp-pcp8-qhf3
Dashboard / Vulnerabilities / GHSA-w4hp-pcp8-qhf3
Summary: Cross-site Scripting in livehelperchat
Details: Stored XSS is found in Settings>Live help configuration>Departments->Departments groups->edit When a user creates a new webhook under the NAME field and puts a payload {{constructor.constructor('alert(1)')()}}, the input gets stored, at user edit groupname , the payload gets executed.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-0387, https://github.com/livehelperchat/livehelperchat/commit/ff70c7dd641b68b9afb170b89ec1ef003a4e3444, https://github.com/livehelperchat/livehelperchat, https://huntr.dev/bounties/2e09035b-8f98-4930-b7e8-7abe5f722b98
Affected packages
Package
Name: remdex/livehelperchat
Purl: pkg:composer/remdex/livehelperchat
Affected ranges
Type: ECOSYSTEM
Events:
