Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16949

Опубликовано: 13 нояб. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). This POST request can be modified to change the message as well as the end recipient of the message. The e-mail address will have the same domain name and user as the product allotted. This can be used in phishing campaigns against users on the same domain.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:enghouse:web_chat:6.1.300.31:*:*:*:*:*:*:*
cpe:2.3:a:enghouse:web_chat:6.2.284.34:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00296
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). This POST request can be modified to change the message as well as the end recipient of the message. The e-mail address will have the same domain name and user as the product allotted. This can be used in phishing campaigns against users on the same domain.

EPSS

Процентиль: 52%
0.00296
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20