EgainCVEs & Vulnerabilities
4 CVEs affecting Egain products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
chat 3mail 1
CVE-2020-15948MEDIUM
eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
30 Jul 2021
6.1
CVSS
CVE-2019-17123HIGH
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)
13 Dec 2019
7.5
CVSS
CVE-2019-13976CRITICAL
eGain Chat 15.0.3 allows unrestricted file upload.
4 Sep 2019
9.8
CVSS
CVE-2019-13975MEDIUM
eGain Chat 15.0.3 allows HTML Injection.
4 Sep 2019
6.1
CVSS
← PrevPage 1 / 1Next →