
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat version ≤ 4.61 allows attackers to execute arbitrary JavaScript by injecting a crafted payload into the Facebook page integration Name Field. The payload is stored and executed when higher-privileged users (e.g., administrators) access or edit the integration settings, resulting in stored Cross Site Scripting (XSS).
Log in as an operator.
Navigate to your Facebook page integration.
Create new Facebook page integration, enter the following payload in the Facebook page integration Name Field:
"><img src="https://raw.githubusercontent.com/thewhiteevil/cve-2025-51398/main/x" onerror="prompt(1);">
Save the changes.
The payload is stored and executed when higher-privileged users (e.g., operator or administrators) access or edit the Facebook page integration, resulting in stored Cross Site Scripting (XSS).
