CVE-2022-0527: Cross-site Scripting (XSS) - Stored in chatwoot/chatwoot
Published Feb 9, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
Affected Software
1 affected component
chatwoot Chatwoot<=2.1.1
Remediation
Event History
Feb 9, 2022
CVE Published
via MITRE·04:20 AM
Data Sourced
via MITRE·04:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0527?
CVE-2022-0527 has a moderate severity rating as it involves stored cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2022-0527?
To fix CVE-2022-0527, upgrade to Chatwoot version 2.2.0 or later.
3
What types of applications does CVE-2022-0527 affect?
CVE-2022-0527 affects web applications built with Chatwoot prior to version 2.2.0.
4
Can CVE-2022-0527 be exploited remotely?
Yes, CVE-2022-0527 can be exploited remotely by attackers to execute scripts on the affected site.
5
What are the potential impacts of CVE-2022-0527?
The potential impacts of CVE-2022-0527 include data theft, session hijacking, and defacement of web applications.