Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat

Valid

Reported on

Aug 25th 2021


✍️ Description

Stored xss via generalsettings

🕵️‍♂️ Proof of Concept

  1. gotohttps://demo.livehelperchat.com/site_admin/chatbox/configuration and update a General settings with xss payload xss"''><img src=x onerror=alert()> and save it .
  2. now try to edit this Chatbox settings using url like https://demo.livehelperchat.com/site_admin/chatbox/generalsettings and see xss is executed

💥 Impact

Stored Xss

We have contacted a member of the livehelperchat team and are waiting to hear back 2 years ago
Remigijus Kiminas validated this vulnerability 2 years ago
k1ssn00b has been awarded the disclosure bounty
The fix bounty is now up for grabs
Remigijus Kiminas marked this as fixed with commit b1c6a7 2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation