CVE-2025-59902 PUBLISHED

HTML injection in NICE Chat

Assigner: INCIBE
Reserved: 23.09.2025 Published: 03.02.2026 Updated: 03.02.2026

HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email sent by the system, which could enable phishing attacks, impersonation, or credential theft.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor NICE
Product NICE Chat
Versions Default: unaffected
  • Version all versions is affected

Credits

  • Leopoldo Angulo Gallego (leoanggal1) finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE