CVE-2026-0483
Last modified
CVE-2026-0483 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the application. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the application. The vulnerability allows arbitrary JavaScript code to be executed in the user's local context.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-0483?
How severe is CVE-2026-0483?
How do I fix CVE-2026-0483?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-0428Insufficient parameter sanitization in TEE SOC Driver could …1.8
- CVE-2026-0432Incorrect default permissions in the installation directory …8.5
- CVE-2026-0438A System Management Mode (SMM) handler could perform a callo…5.4
- CVE-2026-0465A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Maste…5.6
- CVE-2026-0466Improper access control in AMD uProf may allow a local attac…5.5
- CVE-2026-0481Unrestricted IP address binding in the AMD Device Metrics Ex…9.2
- CVE-2026-0484Due to missing authorization check in SAP NetWeaver Applicat…6.5
- CVE-2026-0485SAP BusinessObjects BI Platform allows an unauthenticated at…7.5
- CVE-2026-0486In ABAP based SAP systems a remote enabled function module d…4.3
- CVE-2026-0487SAProuter on Microsoft Windows allows an unauthenticated att…8.4
- CVE-2026-0488An authenticated attacker in SAP CRM and SAP S/4HANA (Script…9.9
- CVE-2026-0489Due to insufficient validation of user-controlled input in t…6.1
Are you affected by CVE-2026-0483?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
