PT-2024-10982 · Chatwoot · Chatwoot

Published

2024-11-15

·

Updated

2024-11-19

·

CVE-2021-3742

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions chatwoot/chatwoot versions prior to 2.5.0
Description A Server-Side Request Forgery (SSRF) vulnerability was discovered, allowing an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a new tab, it can trigger the SSRF, potentially leading to host redirection.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of SVG files or disabling the use of avatars until a patch is applied. Avoid using potentially malicious SVG files as avatars to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2021-3742

Affected Products

Chatwoot