PT-2023-24250 · Verint · Verint Engagement Management
CVE-2023-33257
·
Publicado
2023-08-02
·
Atualizado
2023-08-04
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Verint Engagement Management version 15.3 Update 2023R2
Description
The issue concerns HTML injection via the user data form in the live chat. This allows for potential malicious code injection.
Recommendations
For Verint Engagement Management version 15.3 Update 2023R2, consider restricting access to the user data form in the live chat until a fix is available. As a temporary workaround, disabling the live chat functionality may help minimize the risk of exploitation.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Verint Engagement Management