HTML injection in NICE Chat
Vulnerability Description
HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email sent by the system, which could enable phishing attacks, impersonation, or credential theft.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59902
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Leopoldo Angulo Gallego (leoanggal1)
Affected Vendor
NICE
View all reports →