Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Valid
Reported on
Aug 25th 2021
✍️ Description
Stored xss via generalsettings
🕵️♂️ Proof of Concept
- gotohttps://demo.livehelperchat.com/site_admin/chatbox/configuration and update a General settings with xss payload xss"''><img src=x onerror=alert()> and save it .
- now try to edit this Chatbox settings using url like https://demo.livehelperchat.com/site_admin/chatbox/generalsettings and see xss is executed
💥 Impact
Stored Xss
Occurrences
We have contacted a member of the
livehelperchat
team and are waiting to hear back
2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation