Vulnerability Details CVE-2019-16950
An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2019-16950
-
cpe:2.3:a:enghouse:web_chat:6.1.300.31
-
cpe:2.3:a:enghouse:web_chat:6.2.284.34