CVE-2019-16948
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to determine what is visible on the internal network (as opposed to what general web traffic would see on the product's host). The response from open ports is different than from closed ports. The product does not allow one to change the protocol: anything except http(s) will throw an error; however, it is the type of error that allows one to determine if a port is open or not.
Se descubrió un problema de tipo SSRF en Enghouse Web Chat versión 6.1.300.31. En cualquier petición POST, se puede reemplazar el número de puerto en WebServiceLocation=http://localhost:8085/UCWebServices/ con un rango de puertos para determinar qué es visible en la red interna (a diferencia de lo que el tráfico web general vería en el host del producto). La respuesta de los puertos abiertos es diferente a la de los puertos cerrados. El producto no permite que uno cambie el protocolo: cualquier cosa excepto http(s) arrojará un error; sin embargo, es el tipo de error que permite determinar si un puerto está abierto o no.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-29 CVE Reserved
- 2019-11-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://mjlanders.com/2019/11/07/multiple-vulnerabilities-found-in-enghouse-zeacom-web-chat | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enghouse Search vendor "Enghouse" | Web Chat Search vendor "Enghouse" for product "Web Chat" | 6.1.300.31 Search vendor "Enghouse" for product "Web Chat" and version "6.1.300.31" | - |
Affected
|