CVE-2019-16949: Enghouse Web Chat

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). This POST request can be modified to change the message as well as the end recipient of the message. The e-mail address will have the same domain name and user as the product allotted. This can be used in phishing campaigns against users on the same domain.

Affected products

  • Enghouse Web Chat: version 6.1.300.31 only; version 6.2.284.34 only

Published 2019-11-13. Last modified 2026-06-17.