PT-2025-4309 · Chatwoot · Chatwoot

Ruben Brocke

·

Published

2025-01-09

·

Updated

2025-01-09

·

CVE-2025-21628

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Chatwoot versions prior to 3.16.0
Description The issue concerns a lack of input sanitization for the query operator in conversation and contact filters endpoints. This allows any authenticated actor to run arbitrary SQL within the filter query by adding a tautological WHERE clause.
Recommendations For versions prior to 3.16.0, update to version 3.16.0 to resolve the issue. As a temporary workaround, consider restricting access to the conversation and contact filters endpoints until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-21628
GHSA-G8F9-HH83-RCQ9

Affected Products

Chatwoot