Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
References
Link | Resource |
---|---|
https://github.com/livehelperchat/livehelperchat/commit/ce96791cb4c7420266b668fc234c211914259ba7 | Patch Third Party Advisory |
https://huntr.dev/bounties/a7e40fdf-a333-4a50-8a53-d11b16ce3ec2 | Exploit Patch Third Party Advisory |
Configurations
History
14 Apr 2022, 13:47
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-116 | |
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.8 |
References | (MISC) https://github.com/livehelperchat/livehelperchat/commit/ce96791cb4c7420266b668fc234c211914259ba7 - Patch, Third Party Advisory | |
References | (CONFIRM) https://huntr.dev/bounties/a7e40fdf-a333-4a50-8a53-d11b16ce3ec2 - Exploit, Patch, Third Party Advisory | |
CPE | cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:* |
07 Apr 2022, 19:50
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-04-07 19:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-0935
Mitre link : CVE-2022-0935
CVE.ORG link : CVE-2022-0935
JSON object : View
Products Affected
livehelperchat
- live_helper_chat