PT-2024-10982 · Chatwoot · Chatwoot
Published
2024-11-15
·
Updated
2024-11-19
·
CVE-2021-3742
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
chatwoot/chatwoot versions prior to 2.5.0
Description
A Server-Side Request Forgery (SSRF) vulnerability was discovered, allowing an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a new tab, it can trigger the SSRF, potentially leading to host redirection.
Recommendations
For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of SVG files or disabling the use of avatars until a patch is applied. Avoid using potentially malicious SVG files as avatars to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chatwoot