CVE-2025-51401

A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:*

History

07 Aug 2025, 01:25

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de transferencia de chat de Live Helper Chat v4.60 permite a los atacantes ejecutar scripts web arbitrarios en las páginas mediante la inyección de un payload manipulado en el parámetro del nombre del operador.
First Time Livehelperchat
Livehelperchat live Helper Chat
CPE cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:*
References () https://github.com/LiveHelperChat/livehelperchat/pull/2228/commits/2056503ad96e04467ec9af8d827109b9b9b46223 - () https://github.com/LiveHelperChat/livehelperchat/pull/2228/commits/2056503ad96e04467ec9af8d827109b9b9b46223 - Patch
References () https://github.com/Thewhiteevil/CVE-2025-51401 - () https://github.com/Thewhiteevil/CVE-2025-51401 - Exploit, Third Party Advisory
References () https://www.dropbox.com/scl/fi/efzjql0brniphfh5sgrzn/2025-05-09-14-26-26.mp4?rlkey=z4zpec6wsja5xo0ovq0g5g1tt&st=abbp3gtr&dl=0 - () https://www.dropbox.com/scl/fi/efzjql0brniphfh5sgrzn/2025-05-09-14-26-26.mp4?rlkey=z4zpec6wsja5xo0ovq0g5g1tt&st=abbp3gtr&dl=0 - Exploit

22 Jul 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

21 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 19:15

Updated : 2025-08-07 01:25


NVD link : CVE-2025-51401

Mitre link : CVE-2025-51401

CVE.ORG link : CVE-2025-51401


JSON object : View

Products Affected

livehelperchat

  • live_helper_chat
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')