Junglewise Threat Intelligence

CVE-2025-45960: tawk.to Live Chat stored cross-site scripting in chat input

CVE-2025-45960 · Severity: medium · CVSS 6.1 · Published 2025-07-25

Executive brief

A security vulnerability exists in the tawk.to Live Chat software, which is used by businesses to communicate with website visitors in real-time. An attacker can inject malicious scripts into the chat interface that will execute in the browser of other users, such as site administrators or customers. This could lead to the theft of sensitive session information, unauthorized actions performed on behalf of the user, or damage to the company's brand reputation through website defacement.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in tawk.to Live Chat version 1.6.1 due to improper neutralization of user-supplied input during web page generation (CWE-79). The application fails to validate or encode input provided through the chat interface before storing it on the server and rendering it to other users. An unauthenticated remote attacker can exploit this by submitting a malicious payload (e.g., using HTML event handlers like 'onclick') which executes when a user interacts with the injected element. This allows for session hijacking, credential theft, or redirection to malicious sites. A Proof of Concept (PoC) using an img tag with an onclick event has been disclosed.

Affected products

  • tawk.to Live Chat 1.6.1

Timeline

  • 2025-07-25: advisory: Initial NVD publication date
  • 2025-07-25: disclosed: Public disclosure of the vulnerability and PoC on GitHub

References