VDB
Sign up
HIGH7.5

GHSA-vx8v-g3p3-88vg

Weak password hash in LiveHelperChat

Quick fix

GHSA-vx8v-g3p3-88vg — remdex/livehelperchat: upgrade to the fixed version with the command below.

composer require remdex/livehelperchat:^3.96

Details

The secrethash, which the application relies for multiple security measures, can be brute-forced. The hash is quite small, with only 10 characters of only hexadecimal, making 16^10 possilibities ( 1.099.511.627.776 ). The SHA1 of the secret can be obtained via a captcha string and brute-forced offline with an GPU.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/remdex/livehelperchat
Introduced in: 0Fixed in: 3.96
Fixcomposer require remdex/livehelperchat:^3.96

References