What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live Chat + ChatBot + Cart Saver allows Stored XSS. This issue affects Chatra Live Chat + ChatBot + Cart Saver: from n/a through 1.0.11.
Explanation of Vulnerability in Simple Terms
02Summary
Chatra Live Chat versions up to 1.0.11 contain a cross-site scripting vulnerability that allows authenticated users to disrupt service availability. An attacker with low-level account access can inject malicious input that causes the application to become unavailable to other users. The vulnerability requires network access and an existing user account but no additional user interaction.
What an attacker can do
03Attacker Capabilities
Disrupt service availability for other users through malicious input injection.
Potential impact on your site
04Site Impact
Users may experience service interruptions or unavailability caused by authenticated attackers.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account; network access to the application.
Key dates
06Disclosure timeline
July 4, 2025
CVE published
April 28, 2026
Record updated