VDB
Sign up
HIGH7.7

GHSA-hhr9-7xvh-8xgc

Server side request forgery in LiveHelperChat

Quick fix

GHSA-hhr9-7xvh-8xgc — remdex/livehelperchat: upgrade to the fixed version with the command below.

composer require remdex/livehelperchat:^3.67

Details

SSRF filter bypass port 80, 433 in LiveHelperChat prior to v3.67. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/remdex/livehelperchat
Introduced in: 0Fixed in: 3.67
Fixcomposer require remdex/livehelperchat:^3.67

References