CVE-2019-17176

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/10/2019
Last modified:
16/10/2019

Description

Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:genesys:eservices_chat:*:*:*:*:*:*:*:* 8.1.0 (including) 8.1.200.03 (including)