VDB
Sign up
MEDIUM5.4

GHSA-8wcc-f2vq-h4gx

Cross-site Scripting in livehelperchat

Quick fix

GHSA-8wcc-f2vq-h4gx — remdex/livehelperchat: upgrade to the fixed version with the command below.

composer require remdex/livehelperchat:^3.93

Details

Stored XSS is found in Settings>Live help configuration>Personal Theme>static content. Under the NAME field put a payload {{constructor.constructor('alert(1)')()}} while creating content, and you will see that the input gets stored, and every time the user visits, the payload gets executed.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/remdex/livehelperchat
Introduced in: 0Fixed in: 3.93
Fixcomposer require remdex/livehelperchat:^3.93

References