漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Live Helper Chat: REST API chat update accepts arbitrary chat fields across department boundaries
Vulnerability Description
Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash and status and then access or tamper with the chat through visitor/widget paths. The same write primitive can set operation_admin, which is later emitted as operator-side JavaScript.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Live Helper Chat 安全漏洞
Vulnerability Description
Live Helper Chat是Live Helper Chat个人开发者的一款开源的支持在线聊天的插件。为web平台提供聊天功能。 Live Helper Chat 4.84v版本存在安全漏洞,该漏洞源于REST API聊天更新端点允许用户更新不可读部门的聊天,可能导致访问或篡改聊天内容。
CVSS Information
N/A
Vulnerability Type
N/A