// For flags

CVE-2019-16951

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this domain after the POST request is sent, it retrieves an attacker's data and displays it. Also worth mentioning is the amount of information sent in the request from this product to the attacker: it reveals information the public should not have. This includes pathnames and internal ip addresses.

Se descubrió un problema de tipo remote file include (RFI) en Enghouse Web Chat versión 6.2.284.34. Uno puede reemplazar el atributo localhost con un nombre de dominio propio. Cuando el producto llama a este dominio luego que se envía la petición POST, recupera los datos de un atacante y los muestra. También vale la pena mencionar la cantidad de información enviada en la petición desde este producto hacia un atacante: revela información que el público no debería tener. Esto incluye nombres de ruta y direcciones IP internas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-09-29 CVE Reserved
  • 2019-11-13 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Enghouse
Search vendor "Enghouse"
Web Chat
Search vendor "Enghouse" for product "Web Chat"
6.1.300.31
Search vendor "Enghouse" for product "Web Chat" and version "6.1.300.31"
-
Affected
Enghouse
Search vendor "Enghouse"
Web Chat
Search vendor "Enghouse" for product "Web Chat"
6.2.284.34
Search vendor "Enghouse" for product "Web Chat" and version "6.2.284.34"
-
Affected