Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mortal_Poison

#43243de 53,638
6.1CVSS total
Vulnerabilidades · 1
PT-2019-14983
6.1
2019-10-11
Genesys · Genesys Pureengage Digital · CVE-2019-17176
**Name of the Vulnerable Software and Affected Versions** Genesys PureEngage Digital (eServices) version 8.1.x **Description** The issue allows for XSS attacks through specific JSP files, namely HtmlChatPanel.jsp or HtmlChatFrameSet.jsp, by manipulating certain parameters. These parameters include `ActionColor`, `ClientNickNameColor`, `Email`, `email`, or `email address`. **Recommendations** For Genesys PureEngage Digital (eServices) version 8.1.x, consider restricting access to the HtmlChatPanel.jsp and HtmlChatFrameSet.jsp files until a patch is available. As a temporary workaround, avoid using the parameters `ActionColor`, `ClientNickNameColor`, `Email`, `email`, or `email address` in the affected API endpoints.