Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2022-1530

Disclosure Date: April 29, 2022 (last updated October 07, 2023)
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
Attacker Value
Unknown

CVE-2022-0935

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
Attacker Value
Unknown

CVE-2022-1234

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
Attacker Value
Unknown

CVE-2022-1235

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
Attacker Value
Unknown

CVE-2022-1213

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
Attacker Value
Unknown

CVE-2022-1176

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
Attacker Value
Unknown

CVE-2022-1191

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
Attacker Value
Unknown

CVE-2022-0612

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
Attacker Value
Unknown

CVE-2022-0502

Disclosure Date: February 06, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
Attacker Value
Unknown

CVE-2022-0395

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.