CVE-2019-25737

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft or forced redirects to malicious websites.
Configurations

No configuration.

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Live Chat Unlimited 2.8.3 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes no autenticados inyectar scripts maliciosos a través del campo de entrada del chat. Los atacantes pueden enviar cargas útiles que contienen etiquetas de script y manejadores de eventos que se ejecutan en el área de administración, lo que permite el robo de cookies o redirecciones forzadas a sitios web maliciosos.

10 Jun 2026, 02:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 6.1

04 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 14:16

Updated : 2026-07-22 20:10


NVD link : CVE-2019-25737

Mitre link : CVE-2019-25737

CVE.ORG link : CVE-2019-25737


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')