
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Surname
https://github.com/LiveHelperChat/livehelperchat/
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat version ≤ 4.61 allows attackers to execute arbitrary JavaScript by injecting a crafted payload into the Operator Surname field. This payload is stored and later executed when an admin or higher-privileged user views the Recipients List where the attacker is listed as the Owner.
Log in as an operator.
Navigate to your Operator Surname field.
Create new Operator Surname or Modify the Operator Surname, enter the following payload:
"><img src="https://raw.githubusercontent.com/thewhiteevil/cve-2025-51397/HEAD/x" onerror="prompt(1);">
Save the changes.
This payload is stored and later executed when an admin or higher-privileged user views the Recipients List where the attacker is listed as the Owner.
