Medium severity6.1NVD Advisory· Published Dec 20, 2019· Updated Jun 17, 2026
CVE-2019-19908
CVE-2019-19908
Description
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- phpMyChat-Plus/phpMyChat-Plusdescription
- Range: =1.98
- cpe:2.3:a:ciprianmp:phpmychat-plus:1.98:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- ciprianmp.comnvdVendor Advisory
- cinzinga.github.io/CVE-2019-19908/nvdThird Party Advisory
- sourceforge.net/projects/phpmychat/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.