CVE-2022-1022: Cross-site Scripting (XSS) - Stored in chatwoot/chatwoot
Published Apr 21, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
Affected Software
1 affected component
chatwoot Chatwoot<2.5.0
Remediation
Event History
Apr 21, 2022
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1022?
CVE-2022-1022 has a medium severity rating due to its potential to allow stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-1022?
To fix CVE-2022-1022, upgrade your Chatwoot installation to version 2.5.0 or later.
3
Which versions of Chatwoot are affected by CVE-2022-1022?
CVE-2022-1022 affects all versions of Chatwoot prior to 2.5.0.
4
What type of vulnerability is CVE-2022-1022?
CVE-2022-1022 is a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2022-1022 lead to data exposure?
Yes, CVE-2022-1022 can potentially lead to unauthorized access or exposure of sensitive user information through XSS.