CVE-2019-16950: Enghouse Web Chat

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.

Affected products

  • Enghouse Web Chat: version 6.1.300.31 only; version 6.2.284.34 only

Published 2019-11-13. Last modified 2026-06-17.