Live Helper Chat
cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*
- < 4.72
A stored cross-site scripting vulnerability has been identified in the PDF file upload feature of Live Helper Chat, affecting versions prior to 4.72. This vulnerability allows an attacker to upload a malicious PDF containing an XSS payload, which is executed in the user's context when the file is downloaded and opened via a link generated by the application. The issue enables arbitrary JavaScript code to run in the user's local environment.
Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded PDFs can execute JavaScript in the context of the user who opens them.
Users can upgrade to Live Helper Chat version 4.72 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.