Vulnerability Description
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this domain after the POST request is sent, it retrieves an attacker's data and displays it. Also worth mentioning is the amount of information sent in the request from this product to the attacker: it reveals information the public should not have. This includes pathnames and internal ip addresses.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enghouse | Web Chat | 6.1.300.31 |
Related Weaknesses (CWE)
References
- https://mjlanders.com/2019/11/07/multiple-vulnerabilities-found-in-enghouse-zeacExploitThird Party Advisory
- https://mjlanders.com/2019/11/07/multiple-vulnerabilities-found-in-enghouse-zeacExploitThird Party Advisory
FAQ
What is CVE-2019-16951?
CVE-2019-16951 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this domain after the POST ...
How severe is CVE-2019-16951?
CVE-2019-16951 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16951?
Check the references section above for vendor advisories and patch information. Affected products include: Enghouse Web Chat.