mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
749 B
749 B
CVE-2024-36679
Description
In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method Lcp::saveTranslations()
suffer of a white writer that can inject PHP code into a PHP file.
POC
Reference
Github
No PoCs found on GitHub currently.