CVE-2025-51397

A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
Configurations

Configuration 1 (hide)

cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:*

History

07 Aug 2025, 01:23

Type Values Removed Values Added
References () https://github.com/LiveHelperChat/livehelperchat/pull/2228/commits/2056503ad96e04467ec9af8d827109b9b9b46223 - () https://github.com/LiveHelperChat/livehelperchat/pull/2228/commits/2056503ad96e04467ec9af8d827109b9b9b46223 - Patch
References () https://github.com/Thewhiteevil/CVE-2025-51397 - () https://github.com/Thewhiteevil/CVE-2025-51397 - Exploit, Third Party Advisory
References () https://www.dropbox.com/scl/fi/qrbtcv8bir2i8ielguyi3/2025-05-09-13-58-50.mp4?rlkey=thcbqxuzpm37o73j0ywsu3h3u&st=fhird68s&dl=0 - () https://www.dropbox.com/scl/fi/qrbtcv8bir2i8ielguyi3/2025-05-09-13-58-50.mp4?rlkey=thcbqxuzpm37o73j0ywsu3h3u&st=fhird68s&dl=0 - Exploit
CPE cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) almacenado en el módulo de chat de Facebook de Live Helper Chat v4.60 permite a los atacantes ejecutar scripts web arbitrarios en las páginas mediante la inyección de un payload manipulado en el parámetro Apellido bajo las Listas de destinatarios.
First Time Livehelperchat
Livehelperchat live Helper Chat

22 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-779
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

21 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 19:15

Updated : 2025-08-07 01:23


NVD link : CVE-2025-51397

Mitre link : CVE-2025-51397

CVE.ORG link : CVE-2025-51397


JSON object : View

Products Affected

livehelperchat

  • live_helper_chat
CWE
CWE-779

Logging of Excessive Data