Live Helper Chat Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the PDF file upload feature of Live Helper Chat, affecting versions prior to 4.72. This vulnerability allows an attacker to upload a malicious PDF containing an XSS payload, which is executed in the user's context when the file is downloaded and opened via a link generated by the application. The issue enables arbitrary JavaScript code to run in the user's local environment.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded PDFs can execute JavaScript in the context of the user who opens them.

Remediation

Users can upgrade to Live Helper Chat version 4.72 to address this vulnerability.

Added: Jan 28, 2026, 12:25 PM
Updated: Jan 28, 2026, 12:25 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
5.0
remediation
7.7
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.