Cross-Site Scripting Vulnerability in Genesys PureConnect Interaction Web Tools
CVE-2022-37775

6.1MEDIUM

Key Information:

Vendor

Genesys

Vendor
CVE Published:
16 September 2022

What is CVE-2022-37775?

The Genesys PureConnect Interaction Web Tools Chat Service has a vulnerability that allows attackers to execute Cross-Site Scripting (XSS) through the participant name JSON POST parameter. This issue impacts versions of the product released on or before September 26, 2019, permitting unauthorized scripts to be injected and executed in the web browser of users accessing the printable chat history, potentially compromising sensitive data.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.