We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-0640

Stored XSS in chatwoot/chatwoot



Description

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another admin user when they access the affected dashboard app. The issue is fixed in version 3.5.2.

Reserved 2024-01-17 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 5.6CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Any version before 3.5.2
affected

References

huntr.com/bounties/08b3bebf-ce3c-4416-b75e-1927ba61de85

github.com/...ommit/e39c14460b860d5e3d23d989dd6af48404ad1bb4

cve.org (CVE-2024-0640)

nvd.nist.gov (CVE-2024-0640)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-0640

Support options

Helpdesk Chat, Email, Knowledgebase