Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the application. The vulnerability allows arbitrary JavaScript code to be executed in the user's local context.
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed in the 4.72 version.


Workaround

No workaround given by the vendor.

History

Wed, 28 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the application. The vulnerability allows arbitrary JavaScript code to be executed in the user's local context.
Title Stored Cross-Site Scripting (XSS) vulnerability in LiveHelperChat
First Time appeared Livehelperchat
Livehelperchat livehelperchat
Weaknesses CWE-79
CPEs cpe:2.3:a:livehelperchat:livehelperchat:*:*:*:*:*:*:*:*
Vendors & Products Livehelperchat
Livehelperchat livehelperchat
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-01-28T15:47:13.081Z

Reserved: 2025-12-09T12:06:56.261Z

Link: CVE-2026-0483

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T12:15:52.297

Modified: 2026-01-28T12:15:52.297

Link: CVE-2026-0483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses