CVE-2021-3741: Stored Cross-site Scripting (XSS) in chatwoot/chatwoot
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the avatar is opened in a new page, the custom JavaScript code is executed, leading to potential security risks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3741?
CVE-2021-3741 is classified as a stored cross-site scripting (XSS) vulnerability which can allow attackers to execute scripts in the context of the user's session.
How do I fix CVE-2021-3741?
To mitigate CVE-2021-3741, upgrade Chatwoot to version 2.6 or later to eliminate the vulnerability.
What version of Chatwoot is affected by CVE-2021-3741?
All versions of Chatwoot prior to 2.6 are affected by CVE-2021-3741.
How does CVE-2021-3741 exploit the system?
CVE-2021-3741 exploits the system through the uploading of a malicious SVG file in the user profile settings.
What should users do if they cannot immediately upgrade and are affected by CVE-2021-3741?
If immediate upgrade is not possible, users should restrict SVG file uploads until the system can be secured against CVE-2021-3741.