VDB
Sign up
MEDIUM

GHSA-v4cp-2q7v-hg9q

livehelperchat Server-Side Template Injection

Quick fix

GHSA-v4cp-2q7v-hg9q — remdex/livehelperchat: upgrade to the fixed version with the command below.

composer require remdex/livehelperchat:^4.29

Details

Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/remdex/livehelperchat
Introduced in: 0Fixed in: 4.29
Fixcomposer require remdex/livehelperchat:^4.29

References