CVE-2019-17176: Genesys Eservices Chat

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).

Affected products

  • Genesys Eservices Chat: from 8.1.0, up to and including 8.1.200.03

Published 2019-10-11. Last modified 2026-06-17.