CVE-2025-7435 describes a Cross-Site Scripting (XSS) vulnerability in the LiveHelperChat lhc-php-resque Extension, specifically affecting an unknown part of the /site_admin/lhcphpresque/list/ component. This vulnerability arises from improper handling of the 'queue name' argument, allowing remote attackers to inject malicious scripts. The CVSS score is 3.5 (LOW), indicating a low impact on integrity (I:L) with no confidentiality or availability impact, and requires user interaction (UI:R) for successful exploitation. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks exploit intelligence in common security tools or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| LiveHelperChat | Lhc-Php-Resque Extension | ee1270b35625f552425e32a6a3061cd54b5085c4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.