PT-2019-16000 · Phpmychat · Phpmychat Plus
Cinza
·
Published
2019-12-20
·
Updated
2019-12-31
·
CVE-2019-19908
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyChat-Plus version 1.98
Description
The issue concerns a reflected XSS vulnerability that can be exploited through JavaScript injection into the password reset URL. Specifically, the
pmc username parameter in the pass reset.php URL is vulnerable.Recommendations
For phpMyChat-Plus version 1.98, consider disabling access to the
pass reset.php endpoint until a patch is available, or restrict the use of the pmc username parameter to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmychat Plus