Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat


Reported on

Aug 24th 2021

✍️ Description

Stored xss via rolename

🕵️‍♂️ Proof of Concept

1. First goto and create a role with xss payload xss"''><img src=x onerror=alert()> and save it .
2. now try to edit this role using url like and see xss is executed


We have contacted a member of the livehelperchat team and are waiting to hear back 2 years ago
Remigijus Kiminas validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Remigijus Kiminas marked this as fixed with commit f7584a 2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation