MEDIUM
GHSA-v4cp-2q7v-hg9q
livehelperchat Server-Side Template Injection
Quick fix
GHSA-v4cp-2q7v-hg9q — remdex/livehelperchat: upgrade to the fixed version with the command below.
composer require remdex/livehelperchat:^4.29Details
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/remdex/livehelperchat
Introduced in:
0Fixed in: 4.29Fix
composer require remdex/livehelperchat:^4.29