First published: Thu Aug 27 2020(Updated: )
Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iChat | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23983 is classified as a medium severity vulnerability due to its potential for persistent cross-site scripting attacks.
To fix CVE-2020-23983, update the iChat Realtime PHP Live Support System to the latest version or apply a patch that sanitizes user input to prevent XSS attacks.
CVE-2020-23983 is a persistent cross-site scripting (XSS) vulnerability.
CVE-2020-23983 specifically affects iChat Realtime PHP Live Support System version 1.6.
Yes, CVE-2020-23983 can be exploited remotely if an attacker can inject a malicious script into the chat text fields.