In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T03:37:05.342Z
Reserved: 2024-05-30T00:00:00
Link: CVE-2024-36679
Updated: 2024-08-02T03:37:05.342Z
Status : Awaiting Analysis
Published: 2024-06-19T21:15:57.470
Modified: 2024-11-21T09:22:31.757
Link: CVE-2024-36679
No data.
OpenCVE Enrichment
No data.
Weaknesses