PT-2019-14881 · Enghouse · Enghouse Web Chat

Publicado

2019-11-13

·

Atualizado

2019-11-15

·

CVE-2019-16949

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Enghouse Web Chat versions 6.1.300.31 through 6.2.284.34
Description A security issue in Enghouse Web Chat allows users to modify a POST request, enabling them to change the message and the recipient's email address. This can be exploited in phishing campaigns targeting users within the same domain.
Recommendations For versions 6.1.300.31 and 6.2.284.34, restrict access to the email functionality that allows sending chat logs to prevent potential phishing attacks until a fix is available. As a temporary workaround, consider validating and sanitizing user input for the email address field to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16949

Produtos afetados

Enghouse Web Chat