https://github.com/LiveHelperChat/livehelperchat/
Live Helper Chat 版本 ≤ 4.61 中存在一个存储型跨站脚本(XSS)漏洞,攻击者可通过向 Telegram 机器人用户名参数注入特制载荷,执行任意 JavaScript 代码。该载荷会被存储,并在管理员或更高权限用户查看或编辑 Telegram 机器人用户名时执行。
设置 > 在线客服配置 > Telegram 机器人。 "><img src="https://raw.githubusercontent.com/thewhiteevil/cve-2025-51396/HEAD/x" onerror="prompt(1);">
