Back

MEDIUM

phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL

Published Dec 20, 2019

Description

phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 20, 2019
Updated Aug 5, 2024
Reserved Dec 19, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a