Описание
Cross-Site Request Forgery (CSRF) in livehelperchat
A CSRF issue is found in the audit configuration under settings. It was found that no CSRF token validation is getting done on the server-side. If we remove the CSRF token and keep the CSRF token field empty, the action is getting performed.
Пакеты
Наименование
remdex/livehelperchat
composer
Затронутые версииВерсия исправления
< 3.92
3.92
Связанные уязвимости
CVSS3: 4.3
nvd
около 4 лет назад
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)