Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Valid
Reported on
Jan 27th 2022
Description
LiveHelperChat is vulnerable to Stored XSS at the Name and Surname fields in the User account page.
Payload
{{constructor.constructor('alert(1)')()}}
Steps to reproduce
1.Login then go to User account page (https://demo.livehelperchat.com/site_admin/user/account
)
2.In the Name and Surname fields, input payload {{constructor.constructor('alert(1)')()}}
3.Click Update button then you will see the XSS popup will display. Moreover, when you go to the dashboard, the XSS popup will also display here.
Impact
This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
Occurrences
We are processing your report and will contact the
livehelperchat
team within 24 hours.
a year ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
edit.tpl.php#L91-L99
has been validated
to join this conversation