
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Chat Name Field Triggers on Chat Owner Transfer
https://github.com/LiveHelperChat/livehelperchat/
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat version ≤ 4.61 allows attackers to execute arbitrary JavaScript by injecting a crafted payload into the Operator Chat Name Field Triggers on Chat Owner Transfer Functionality on Live Helper Chat.
Log in as an operator.
Navigate to your operator settings page.
In the Name field, enter the following payload:
"><img src="https://raw.githubusercontent.com/thewhiteevil/cve-2025-51401/HEAD/x" onerror="prompt(1);">
Save the changes.
Initiate a chat with a visitor.
Transfer the chat to another operator — the XSS payload executes in the receiving operator’s chat interface.
