PT-2019-14983 · Genesys · Genesys Pureengage Digital
Luis Eduardo Jácome V
+1
·
Published
2019-10-11
·
Updated
2019-10-16
·
CVE-2019-17176
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Genesys PureEngage Digital (eServices) version 8.1.x
Description
The issue allows for XSS attacks through specific JSP files, namely HtmlChatPanel.jsp or HtmlChatFrameSet.jsp, by manipulating certain parameters. These parameters include
ActionColor, ClientNickNameColor, Email, email, or email address.Recommendations
For Genesys PureEngage Digital (eServices) version 8.1.x, consider restricting access to the HtmlChatPanel.jsp and HtmlChatFrameSet.jsp files until a patch is available. As a temporary workaround, avoid using the parameters
ActionColor, ClientNickNameColor, Email, email, or email address in the affected API endpoints.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Genesys Pureengage Digital