CVE-2019-16950

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/11/2019
Last modified:
15/11/2019

Description

An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enghouse:web_chat:6.1.300.31:*:*:*:*:*:*:*
cpe:2.3:a:enghouse:web_chat:6.2.284.34:*:*:*:*:*:*:*