HIGH7.7
GHSA-hhr9-7xvh-8xgc
Server side request forgery in LiveHelperChat
Quick fix
GHSA-hhr9-7xvh-8xgc — remdex/livehelperchat: upgrade to the fixed version with the command below.
composer require remdex/livehelperchat:^3.67Details
SSRF filter bypass port 80, 433 in LiveHelperChat prior to v3.67. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/remdex/livehelperchat
Introduced in:
0Fixed in: 3.67Fix
composer require remdex/livehelperchat:^3.67References
- https://nvd.nist.gov/vuln/detail/CVE-2022-1213[ADVISORY]
- https://github.com/LiveHelperChat/livehelperchat/issues/1752[WEB]
- https://github.com/livehelperchat/livehelperchat/commit/abc9599ee7aded466ca216741dcaea533c908111[WEB]
- https://github.com/livehelperchat/livehelperchat[PACKAGE]
- https://huntr.dev/bounties/084387f6-5b9c-4017-baa2-5fcf65b051e1[WEB]