CVE-2023-2109: Cross-site Scripting (XSS) - DOM in chatwoot/chatwoot
Published Apr 17, 2023
·Updated
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
Affected Software
1 affected component
chatwoot Chatwoot<2.14.0
Remediation
Event History
Apr 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2109?
The severity of CVE-2023-2109 is medium with a severity value of 6.1.
2
How does CVE-2023-2109 impact GitHub repository chatwoot/chatwoot?
CVE-2023-2109 allows for Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to version 2.14.0.
3
How can I fix CVE-2023-2109 in chatwoot/chatwoot?
To fix CVE-2023-2109, upgrade chatwoot/chatwoot to version 2.14.0 or above.
4
What is the Common Weakness Enumeration (CWE) of CVE-2023-2109?
The Common Weakness Enumeration (CWE) of CVE-2023-2109 is CWE-79.
5
Where can I find more information about CVE-2023-2109?
You can find more information about CVE-2023-2109 at the following references: [Link 1](https://github.com/chatwoot/chatwoot/commit/a06a5a574ad908b0ef2db7b47d05c3774eeb493d), [Link 2](https://huntr.dev/bounties/fd5999fd-b1fd-44b4-ae2e-8f95b5c3d1b6).