PT-2020-9339 · Verint · Verint Impact 360

Ryan Delaney

·

Published

2020-07-14

·

Updated

2020-07-16

·

CVE-2019-12773

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Verint Impact 360 version 15.1
Description: An issue was discovered in Verint Impact 360 where the helpURL parameter at the "/wfo/help/help popup.jsp" endpoint can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this product is installed, given the attacker can convince a victim to visit a crafted link.
Recommendations: For Verint Impact 360 version 15.1, consider restricting access to the helpURL parameter at the "/wfo/help/help popup.jsp" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the helpURL parameter until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12773

Affected Products

Verint Impact 360