S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-19908 Scanner

CVE-2019-19908 scanner - Cross-Site Scripting (XSS) vulnerability in phpMyChat-Plus

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-19908
6.1
CVSS

phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

PhpMyChat-Plus is a free and open-source web-based chat application that runs on PHP and MySQL. It is designed for small to medium-sized communities and is used to provide a chat room feature on websites. The application provides a user-friendly interface and enables communication between users in real-time.

The CVE-2019-19908 vulnerability detected in this product is a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious code into the URL of the password reset page. Specifically, the pmc_username parameter in the pass_reset.php file is susceptible to JavaScript injection.

This vulnerability can lead to serious consequences for both users and websites. For users, their sensitive data, including login credentials, can be hijacked by an attacker, putting their personal information at risk. For websites, the vulnerability can potentially lead to data breaches, loss of reputation, and even legal consequences.

At s4e.io, we offer a platform that allows users to scan and identify vulnerabilities in their digital assets quickly and easily. With our advanced features, users can get a comprehensive overview of their websites' security posture and receive real-time alerts about potential threats. By using our platform, businesses and website owners can rest assured that their digital assets are secure and protected from the latest cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website administrators should take the following precautions:

  • Upgrade to the latest version of phpMyChat-Plus 
  • Apply security patches when they become available 
  • Implement input validation and sanitization measures 
  • Use a web application firewall (WAF) to filter out malicious traffic 
  • Educate users about safe browsing practices, such as not clicking on suspicious links or opening unknown attachments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-19908 scanner - Cross-Site Scripting (XSS) vulnerability in phpMyChat-Plus | S4E