VDB
Sign up
MEDIUM4.3

GHSA-6jmh-9gqm-5xrx

Cross-Site Request Forgery (CSRF) in livehelperchat

Quick fix

GHSA-6jmh-9gqm-5xrx — remdex/livehelperchat: upgrade to the fixed version with the command below.

composer require remdex/livehelperchat:^3.92

Details

A CSRF issue is found in the audit configuration under settings. It was found that no CSRF token validation is getting done on the server-side. If we remove the CSRF token and keep the CSRF token field empty, the action is getting performed.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/remdex/livehelperchat
Introduced in: 0Fixed in: 3.92
Fixcomposer require remdex/livehelperchat:^3.92

References