
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat version ≤ 4.61 allows attackers to execute arbitrary JavaScript by injecting a crafted payload into the Telegram Bot Username parameter. This payload is stored and later executed when an admin or higher-privileged user views or edits the Telegram Bot Username.
Settings > Live Help Configuration > Telegram Bot. "><img src="https://raw.githubusercontent.com/thewhiteevil/cve-2025-51396/main/x" onerror="prompt(1);">
