Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash and status and then access or tamper with the chat through visitor/widget paths. The same write primitive can set operation_admin, which is later emitted as operator-side JavaScript.
References
Configurations
No configuration.
History
14 May 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/LiveHelperChat/livehelperchat/security/advisories/GHSA-hjqq-qmvj-9whm - |
14 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 19:16
Updated : 2026-05-15 14:44
NVD link : CVE-2026-44633
Mitre link : CVE-2026-44633
CVE.ORG link : CVE-2026-44633
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
