PT-2023-24250 · Verint · Verint Engagement Management

CVE-2023-33257

·

Publicado

2023-08-02

·

Atualizado

2023-08-04

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Verint Engagement Management version 15.3 Update 2023R2
Description The issue concerns HTML injection via the user data form in the live chat. This allows for potential malicious code injection.
Recommendations For Verint Engagement Management version 15.3 Update 2023R2, consider restricting access to the user data form in the live chat until a fix is available. As a temporary workaround, disabling the live chat functionality may help minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33257

Produtos afetados

Verint Engagement Management