CVE Database
/

CVE-2021-3741

Back to search

CVE-2021-3741

Published: Nov 15, 2024

Modified: Nov 20, 2024

PUBLISHED

CVSS v3.0

7.8

HIGH

Description

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the avatar is opened in a new page, the custom JavaScript code is executed, leading to potential security risks.

VendorProductVersions

chatwoot

chatwoot/chatwoot

affected
unspecified - < 2.6

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now