Super 8 livechat SDK - Cross-site Scripting
Published Apr 29, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.43%
Description
Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.
Affected products
-
Affected
- ≥ earlier, ≤ 4.5.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Super 8 | livechat SDK | unaffected | Affected
|
No data.
-
Affected
- n/a
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Super 8 | livechat SDK | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 4.6.0 or later version(Patch has been released on 2024/3/18. Please refreshing the webpage to automatically update it.)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32852 Advisory
- https://www.twcert.org.tw/tw/cp-132-7779-35562-1.html third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32852 | Advisory | |
| https://www.twcert.org.tw/tw/cp-132-7779-35562-1.html | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data