vendor:
Live Chat Unlimited
by:
m0ze
8.8
CVSS
HIGH
Stored XSS Injection
79
CWE
Product Name: Live Chat Unlimited
Affected Version From: 2.8.3
Affected Version To: 2.8.3
Patch Exists: NO
Related CWE: N/A
CPE: a:screets:live_chat_unlimited
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / Parrot OS
2019
Live Chat Unlimited v2.8.3 Stored XSS Injection
Weak security measures like bad input field data filtering has been discovered in the «Live Chat Unlimited». Current version of this premium WordPress plugin is 2.8.3. Go to the demo website https://site.com/try/lcx/night-bird/ and open chat window by clicking on «Open/close» link, then click on «Online mode» to go online. Use your payload inside input field and press [Enter]. Provided exaple payloads working on the admin area, so it's possible to steal admin cookies or force a redirect to any other website.
Mitigation:
Input validation and sanitization should be implemented to prevent XSS attacks.