Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| remdex/livehelperchat(Packagist) | 0 | 4.29 | N/A |
CVSS Metrics