CVE-2019-16949
Last modified
CVE-2019-16949 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). This POST request can be modified to change the message as well as the end recipient of the message. The e-mail address will have the same domain name and user as the product allotted. This can be used in phishing campaigns against users on the same domain.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enghouse | Web Chat | 6.1.300.31 |
| Enghouse | Web Chat | 6.2.284.34 |
References
- https://mjlanders.com/2019/11/07/multiple-vulnerabilities-found-in-enghouse-zeacom-web-chat/Exploit, Third Party Advisory
- https://mjlanders.com/2019/11/07/multiple-vulnerabilities-found-in-enghouse-zeacom-web-chat/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16949?
How severe is CVE-2019-16949?
How do I fix CVE-2019-16949?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16935The documentation XML-RPC server in Python through 2.7.16, 3…6.1
- CVE-2019-1694A vulnerability in the TCP processing engine of Cisco Adapti…8.6
- CVE-2019-16941NSA Ghidra through 9.0.4, when experimental mode is enabled,…9.8
- CVE-2019-16942A Polymorphic Typing issue was discovered in FasterXML jacks…9.8
- CVE-2019-16943A Polymorphic Typing issue was discovered in FasterXML jacks…9.8
- CVE-2019-16948An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31…9.8
- CVE-2019-1695A vulnerability in the detection engine of Cisco Adaptive Se…6.5
- CVE-2019-16950An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 …6.1
- CVE-2019-16951A remote file include (RFI) issue was discovered in Enghouse…5.3
- CVE-2019-16954SolarWinds Web Help Desk 12.7.0 allows HTML injection via a …5.4
- CVE-2019-16955SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded S…5.4
- CVE-2019-16956SolarWinds Web Help Desk 12.7.0 allows XSS via the Request T…5.4
Are you affected by CVE-2019-16949?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
