Skip to content

Commit

Permalink
Update 2024-06-18-livechatpro.md
Browse files Browse the repository at this point in the history
  • Loading branch information
touchweb-vincent authored Jun 19, 2024
1 parent 9eb81e5 commit dd44bcd
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion _posts/2024-06-18-livechatpro.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro), a gue

Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file which will lead to critical RCE.

**WARNING** : Author refuse to patch the vulnerability so you should consider to uninstall it. There is strong design issue which cannot be fixed by a hotfix. Version tagged as impacted is the only version we had time to produce a POC for it, author has updated things in newer versions but its token is still predictible. So you should consider that all versions are impacted.
**WARNING** : Author refuse to patch the vulnerability so you should consider to uninstall it. There is strong design issue which cannot be fixed by a hotfix. Version tagged as impacted is the only version we had time to produce a POC for it, author has updated things in newer versions but its token is still predictable. So you should consider that all versions are impacted.

## CVSS base metrics

Expand Down

0 comments on commit dd44bcd

Please sign in to comment.