QID 730729

Date Published: 2023-02-22

QID 730729: Chatwoot Improper Authorization Vulnerability

Chatwoot is an open-source as well as cloud-based customer engagement platform.

Affected Versions:
Chatwoot Engine versions prior to v2.8.0

QID Detection Logic(Unauthenticated):
The QID checks for vulnerable version of Chatwoot via querying endpoint "app/login".

The vulnerability in edit team function lead an user add another user via ID to Team, alternatively know the email of every user in Chatwoot.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Customers are advised to install Chatwoot v2.8.0 or later version to remediate this vulnerability.

    CVEs related to QID 730729

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-2901 URL Logo huntr.dev/bounties/cf46e0a6-f1b5-4959-a952-be9e4bac03fe/