CVE-2022-0642
30.05.2022, 09:15
The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.
Vendor | Product | Version |
---|---|---|
jivochat | jivochat | 𝑥 < 1.3.5.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration