Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat

Valid

Reported on

Aug 24th 2021


✍️ Description

Stored xss via rolename

🕵️‍♂️ Proof of Concept

1. First goto https://demo.livehelperchat.com/site_admin/permission/roles and create a role with xss payload xss"''><img src=x onerror=alert()> and save it .
2. now try to edit this role using url like https://demo.livehelperchat.com/site_admin/permission/editrole/2 and see xss is executed

Occurences

We have contacted a member of the livehelperchat team and are waiting to hear back a month ago
Remigijus Kiminas validated this vulnerability a month ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Remigijus Kiminas confirmed that a fix has been merged on f7584a a month ago
The fix bounty has been dropped