CVE-2025-51397 is a stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60. An authenticated attacker can inject malicious web scripts into the "Surname" parameter under Recipient' Lists, which are then executed when viewed by another user. This vulnerability has a CVSS score of 5.4 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and leading to low impact on confidentiality and integrity. While not currently on the CISA KEV list or actively exploited, exploit code is publicly available via ExploitDB (EDB-52377), and its FAUCET Risk Score is 86/100, suggesting a higher potential for future exploitation despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.61CPE matchmatch criteria | cpe:2.3:a:livehelperchat:live_helper_chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.