Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Administrator Extension MEDIUM 6.1
CVE-2023-23208

Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin…

Fix: 9.0.105.15+
Fix from $1,600 2023-08-13
Tftp Server HIGH 8.8
CVE-2023-29930

An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login…

Mitigation only
Fix from $1,950 2023-05-10
Pureconnect MEDIUM 6.1
CVE-2022-37775

Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the part…

Fix: after 2022-09-26
Fix from $1,600 2022-09-16
Workforce Management MEDIUM 6.1
CVE-2021-26787

A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.

Mitigation only
Fix from $1,600 2021-12-15
Intelligent Workload Distribution Manager HIGH 7.2
CVE-2021-40860

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execu…

Fix: 9.0.013.11+
Fix from $1,950 2021-12-08
Intelligent Workload Distribution Manager HIGH 7.2
CVE-2021-40861

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbi…

Fix: 9.0.017.07+
Fix from $1,950 2021-12-08
Eservices Chat MEDIUM 6.1
CVE-2019-17176

Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email…

Fix: after 8.1.200.03
Fix from $1,600 2019-10-11