PT-2025-38955 · Kommo · Kommo Website Chat Button

Peter Thaleikis

·

Published

2025-09-22

·

Updated

2025-09-23

·

CVE-2025-58666

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kommo Website Chat Button versions through 1.3.1
Description An authorization issue exists in the Kommo Website Chat Button integration, allowing exploitation due to incorrectly configured access control security levels.
Recommendations Update Kommo Website Chat Button to a version later than 1.3.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-58666

Affected Products

Kommo Website Chat Button