{"id":"BIT-livehelperchat-2020-26135","details":"Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.","aliases":["CVE-2020-26135"],"modified":"2024-03-06T11:25:28.861Z","published":"2024-03-06T10:59:52.070Z","database_specific":{"severity":"Medium","cpes":["cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://github.com/LiveHelperChat/livehelperchat/commit/a131b937dd6a87271ed1c0c8b8deb8710cf78f58"},{"type":"WEB","url":"https://github.com/rekter0/exploits/tree/master/CVE-2020-26134"},{"type":"WEB","url":"https://livehelperchat.com/3.44v-security-update-and-few-other-bits-586a.html"},{"type":"WEB","url":"https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63"}],"affected":[{"package":{"name":"livehelperchat","ecosystem":"Bitnami","purl":"pkg:bitnami/livehelperchat"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.44.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/livehelperchat/BIT-livehelperchat-2020-26135.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}],"schema_version":"1.7.3"}