CVE-2024-27516

EPSS 3.2%

livehelperchat Server-Side Template Injection

Published: 2/29/2024Modified: 12/1/2024
Also known as:GHSA-v4cp-2q7v-hg9q

Description

Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.

Affected packages (1)

References (4)