Description
Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft or forced redirects to malicious websites.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
m0ze
References
www.exploit-db.com/exploits/47037 (ExploitDB-47037)
screets.com/ (Official Product Homepage)
codecanyon.net/item/wordpress-live-chat-plugin/3952877 (Product Reference)
www.vulncheck.com/...t-unlimited-stored-cross-site-scripting (VulnCheck Advisory: Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting)