Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2023-23208

Disclosure Date: August 13, 2023 (last updated October 08, 2023)
Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.
Attacker Value
Unknown

CVE-2023-29930

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.
Attacker Value
Unknown

CVE-2022-37775

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.
Attacker Value
Unknown

CVE-2021-26787

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.
Attacker Value
Unknown

CVE-2021-40861

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.
Attacker Value
Unknown

CVE-2021-40860

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.
Attacker Value
Unknown

CVE-2019-17176

Disclosure Date: October 11, 2019 (last updated November 27, 2024)
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).