Back

MEDIUM

Super 8 livechat SDK - Cross-site Scripting

Published Apr 29, 2024

Description

Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.

Affected products

Remediation

Vendor solution

Update to 4.6.0 or later version(Patch has been released on 2024/3/18. Please refreshing the webpage to automatically update it.)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner twcert
Published Apr 29, 2024
Updated Aug 1, 2024
Reserved Apr 29, 2024

CISA Vulnrichment

Updated Apr 29, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner twcert
Published Apr 29, 2024
Updated Aug 1, 2024

GitHub

No data