QID 730729
Date Published: 2023-02-22
QID 730729: Chatwoot Improper Authorization Vulnerability
Chatwoot is an open-source as well as cloud-based customer engagement platform.
Affected Versions:
Chatwoot Engine versions prior to v2.8.0
QID Detection Logic(Unauthenticated):
The QID checks for vulnerable version of Chatwoot via querying endpoint "app/login".
The vulnerability in edit team function lead an user add another user via ID to Team, alternatively know the email of every user in Chatwoot.
Solution
Customers are advised to install Chatwoot v2.8.0 or later version to remediate this vulnerability.
Vendor References
- CVE-2022-2901 -
huntr.dev/bounties/cf46e0a6-f1b5-4959-a952-be9e4bac03fe/
CVEs related to QID 730729
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-2901 |
|