← Back to browse · API

CVE-2024-36679

Severity
CRITICAL
CVSS
10.0
EPSS
0.00606
Risk score
40.21
CISA KEV
No
PoC
No
Published
2024-06-19
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-36184, GHSA-8FQ9-7WWX-42V9
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-36184

Description

In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file.

References