PT-2025-43902 · Chatwoot · Chatwoot
Fpatrik
·
Published
2025-10-27
·
Updated
2025-10-27
·
CVE-2025-12245
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
chatwoot versions prior to 4.7.0
Description
A flaw exists in chatwoot that allows for origin validation errors. This issue is located within the
initPostMessageCommunication function of the app/javascript/sdk/IFrameHelper.js file, part of the Widget component. Manipulation of the baseUrl argument can trigger this flaw. Remote exploitation is possible.Recommendations
Update to a version of chatwoot greater than 4.7.0.
Exploit
Fix
Insufficient Verification of Data Authenticity
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chatwoot