This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Chatwoot First view 2021-07-16
Product Chatwoot Last view 2024-11-15
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:chatwoot:chatwoot

Activity : Overall

Related : CVE

  Date Alert Description
8.8 2024-11-15 CVE-2021-3742

A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a new tab, it can trigger the SSRF, potentially leading to host redirection.

5.4 2024-11-15 CVE-2021-3741

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the avatar is opened in a new page, the custom JavaScript code is executed, leading to potential security risks.

6.1 2023-04-17 CVE-2023-2109

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.

9.8 2022-10-28 CVE-2022-3741

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.

7.1 2022-09-06 CVE-2022-2901

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

5.4 2022-08-19 CVE-2022-1021

Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.

6.1 2022-08-19 CVE-2022-0542

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

5.4 2022-04-21 CVE-2022-1022

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.

6.1 2022-02-09 CVE-2022-0527

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

6.1 2022-02-09 CVE-2022-0526

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

6.5 2022-02-09 CVE-2021-3813

Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

7.5 2021-07-16 CVE-2021-3649

chatwoot is vulnerable to Inefficient Regular Expression Complexity

CWE : Common Weakness Enumeration

%idName
60% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
20% (1) CWE-639 Access Control Bypass Through User-Controlled Key
20% (1) CWE-307 Improper Restriction of Excessive Authentication Attempts