HTML injection in NICE Chat

Posted date 02/02/2026
Identificador
INCIBE-2026-076
Importance
4 - High
Affected Resources

NICE Chat System.

Description

INCIBE has coordinated the publication of a high-severity vulnerability affecting the NICE Chat system, a customer service and contact center solution. The vulnerability was discovered by Leopoldo Angulo Gallego (leoanggal1).

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:

  • CVE-2025-59902: CVSS v4.0: 7.1 | CVSS AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N | CWE-79
Solution

There is no solution reported at this time.

Detail

CVE-2025-59902: HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email sent by the system, which could enable phishing attacks, impersonation, or credential theft. 

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2025-59902 Alta no NICE
References list