HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email sent by the system, which could enable phishing attacks, impersonation, or credential theft.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-02-03 10:15
Updated : 2026-02-03 16:44
NVD link : CVE-2025-59902
Mitre link : CVE-2025-59902
CVE.ORG link : CVE-2025-59902
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
