Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-7779-35562-1.html |
Configurations
No configuration.
History
29 Apr 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-29 06:15
Updated : 2024-04-29 12:42
NVD link : CVE-2024-4302
Mitre link : CVE-2024-4302
CVE.ORG link : CVE-2024-4302
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')