VYPR

Live Chat

by Livezilla

CVEs (2)

  • CVE-2020-9758CriMar 9, 2020
    risk 0.63cvss 9.6epss 0.02

    An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from…

  • CVE-2018-10810MedMay 16, 2018
    risk 0.40cvss 6.1epss 0.01

    chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.