PT-2022-13596 · Chatwoot · Chatwoot

Published

2022-08-19

·

Updated

2022-08-19

·

CVE-2022-1021

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions chatwoot/chatwoot versions prior to 2.6.0
Description The issue concerns insecure storage of sensitive information in the GitHub repository chatwoot/chatwoot.
Recommendations For versions prior to 2.6.0, update to version 2.6.0 or later to resolve the issue.

Exploit

Fix

XSS

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-1021

Affected Products

Chatwoot