PT-2019-14882 · Enghouse · Enghouse Web Chat
Publicado
2019-11-13
·
Atualizado
2019-11-15
·
CVE-2019-16950
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Enghouse Web Chat versions 6.1.300.31 through 6.2.284.34
Description
A cross-site scripting (XSS) issue was found, allowing the insertion of user-supplied JavaScript through the
QueueName parameter of a GET request.Recommendations
For versions 6.1.300.31 and 6.2.284.34, avoid using the
QueueName parameter in the affected GET request until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Enghouse Web Chat