Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 03 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email sent by the system, which could enable phishing attacks, impersonation, or credential theft. | |
| Title | HTML injection in NICE Chat | |
| First Time appeared |
Nice
Nice nice Chat |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:nice:nice_chat:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Nice
Nice nice Chat |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-03T17:16:31.965Z
Reserved: 2025-09-23T10:24:09.538Z
Link: CVE-2025-59902
Updated: 2026-02-03T17:16:27.032Z
Status : Deferred
Published: 2026-02-03T10:15:56.160
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59902
No data.
OpenCVE Enrichment
No data.