CVE-2019-16949 affects Enghouse Web Chat versions 6.1.300.31 and 6.2.284.34, allowing an authenticated user to modify a chat log archive request. This enables an attacker to alter the message content and recipient email address, provided the recipient shares the same domain as the product's allotted user. The vulnerability has a CVSS score of 6.5 (Medium), indicating a low-complexity network attack that can lead to high integrity impact, primarily through phishing campaigns. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1.300.31CPE matchmatch criteria | cpe:2.3:a:enghouse:web_chat:6.1.300.31:*:*:*:*:*:*:* | ||
6.2.284.34CPE matchmatch criteria | cpe:2.3:a:enghouse:web_chat:6.2.284.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.