Vulnerability Description
Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the response from the POST request is displayed, and any JavaScript returned from the external server is executed in the browser. This is related to CVE-2019-16951.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enghouse | Web Chat | 6.2.284.34 |
Related Weaknesses (CWE)
References
- http://burninatorsec.blogspot.com/2020/09/cve-2020-13972-xss-via-ssrf-in.htmlExploitThird Party Advisory
- http://burninatorsec.blogspot.com/2020/09/cve-2020-13972-xss-via-ssrf-in.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-13972?
CVE-2020-13972 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the response from the POST request is displayed, and any JavaScript returned from th...
How severe is CVE-2020-13972?
CVE-2020-13972 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13972?
Check the references section above for vendor advisories and patch information. Affected products include: Enghouse Web Chat.