Tawk Live Chat
cpe:2.3:a:tawk:tawk.to_live_chat:*:*:*:*:wordpress:*:*
A stored cross-site scripting vulnerability has been identified in Tawk Live Chat. This issue allows an attacker to execute JavaScript in the browser of a victim by uploading a malicious PDF containing a JavaScript payload through the chatbot. The application stores the PDF and later displays it to other users without adequate sanitization. Exploitation of this vulnerability could lead to the theft of sensitive user information, such as session cookies, or allow actions to be performed on behalf of the user.
Exploitation of this vulnerability could result in stored cross-site scripting, allowing for the execution of malicious scripts in the context of the user's browser.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.