Bitnami package
livehelperchat
pkg:bitnami/livehelperchat
Vulnerabilities (29)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-1530 | — | < 3.99.0 | 3.99.0 | Apr 29, 2022 | Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application. | ||
| CVE-2022-0935 | — | < 3.97.0 | 3.97.0 | Apr 7, 2022 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. | ||
| CVE-2022-1234 | — | < 3.97.0 | 3.97.0 | Apr 6, 2022 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device. | ||
| CVE-2022-1235 | — | < 3.96.0 | 3.96.0 | Apr 5, 2022 | Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2022-1213 | — | < 3.97.0 | 3.97.0 | Apr 5, 2022 | SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191 | ||
| CVE-2022-1176 | — | < 3.96.0 | 3.96.0 | Mar 31, 2022 | Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2022-1191 | — | < 3.96.0 | 3.96.0 | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2022-0612 | — | < 3.92.0 | 3.92.0 | Feb 16, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0502 | — | < 3.92.0 | 3.92.0 | Feb 6, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0395 | — | < 3.93.0 | 3.93.0 | Jan 28, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0394 | — | < 3.93.0 | 3.93.0 | Jan 28, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0375 | — | < 3.93.0 | 3.93.0 | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0374 | — | < 3.93.0 | 3.93.0 | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0266 | — | < 3.92.0 | 3.92.0 | Jan 19, 2022 | Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v. | ||
| CVE-2022-0226 | — | < 2.0.0 | 2.0.0 | Jan 14, 2022 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0231 | — | < 3.91.0 | 3.91.0 | Jan 14, 2022 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0083 | — | < 3.91.0 | 3.91.0 | Jan 4, 2022 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | ||
| CVE-2021-4175 | — | < 3.91.0 | 3.91.0 | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4176 | — | < 3.91.0 | 3.91.0 | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4179 | — | < 3.91.0 | 3.91.0 | Dec 28, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- CVE-2022-1530Apr 29, 2022affected < 3.99.0fixed 3.99.0
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
- CVE-2022-0935Apr 7, 2022affected < 3.97.0fixed 3.97.0
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
- CVE-2022-1234Apr 6, 2022affected < 3.97.0fixed 3.97.0
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
- CVE-2022-1235Apr 5, 2022affected < 3.96.0fixed 3.96.0
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- CVE-2022-1213Apr 5, 2022affected < 3.97.0fixed 3.97.0
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
- CVE-2022-1176Mar 31, 2022affected < 3.96.0fixed 3.96.0
Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- CVE-2022-1191Mar 31, 2022affected < 3.96.0fixed 3.96.0
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- CVE-2022-0612Feb 16, 2022affected < 3.92.0fixed 3.92.0
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- CVE-2022-0502Feb 6, 2022affected < 3.92.0fixed 3.92.0
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- CVE-2022-0395Jan 28, 2022affected < 3.93.0fixed 3.93.0
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- CVE-2022-0394Jan 28, 2022affected < 3.93.0fixed 3.93.0
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- CVE-2022-0375Jan 26, 2022affected < 3.93.0fixed 3.93.0
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- CVE-2022-0374Jan 26, 2022affected < 3.93.0fixed 3.93.0
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- CVE-2022-0266Jan 19, 2022affected < 3.92.0fixed 3.92.0
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
- CVE-2022-0226Jan 14, 2022affected < 2.0.0fixed 2.0.0
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
- CVE-2022-0231Jan 14, 2022affected < 3.91.0fixed 3.91.0
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
- CVE-2022-0083Jan 4, 2022affected < 3.91.0fixed 3.91.0
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
- CVE-2021-4175Dec 29, 2021affected < 3.91.0fixed 3.91.0
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-4176Dec 29, 2021affected < 3.91.0fixed 3.91.0
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-4179Dec 28, 2021affected < 3.91.0fixed 3.91.0
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Page 1 of 2