CVE-2025-45960
MEDIUMtawk.to < 1.6.1 - Stored Cross-Site Scripting via User-Supplied Input
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-45960. PoCs published by pracharapol.
AI-analyzed exploit summary This repository contains a proof-of-concept for a stored XSS vulnerability in tawk.to Live Chat version 1.6.1. The exploit demonstrates how malicious JavaScript can be injected via the chat input field and executed in the context of a user's browser.
Description
Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding
Exploits (1)
This repository contains a proof-of-concept for a stored XSS vulnerability in tawk.to Live Chat version 1.6.1. The exploit demonstrates how malicious JavaScript can be injected via the chat input field and executed in the context of a user's browser.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N