{"id":"GHSA-hhr9-7xvh-8xgc","summary":"Server side request forgery in LiveHelperChat","details":"SSRF filter bypass port 80, 433 in LiveHelperChat prior to v3.67. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191","aliases":["BIT-livehelperchat-2022-1213","CVE-2022-1213"],"modified":"2023-12-06T01:01:51.339642Z","published":"2022-04-06T00:01:32Z","database_specific":{"severity":"HIGH","github_reviewed_at":"2022-04-07T15:44:18Z","nvd_published_at":"2022-04-05T04:15:00Z","github_reviewed":true,"cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1213"},{"type":"WEB","url":"https://github.com/LiveHelperChat/livehelperchat/issues/1752"},{"type":"WEB","url":"https://github.com/livehelperchat/livehelperchat/commit/abc9599ee7aded466ca216741dcaea533c908111"},{"type":"PACKAGE","url":"https://github.com/livehelperchat/livehelperchat"},{"type":"WEB","url":"https://huntr.dev/bounties/084387f6-5b9c-4017-baa2-5fcf65b051e1"}],"affected":[{"package":{"name":"remdex/livehelperchat","ecosystem":"Packagist","purl":"pkg:composer/remdex/livehelperchat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.67"}]}],"versions":["1.74","1.81","1.82","1.83","1.84","1.85","1.86","1.87","1.88","1.89","1.90","1.91","1.93","1.94","1.95","1.98","2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-hhr9-7xvh-8xgc/GHSA-hhr9-7xvh-8xgc.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L"}]}