CVE-2025-12245: chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12245?
The severity of CVE-2025-12245 is high due to the risk of remote exploitation through origin validation errors.
How do I fix CVE-2025-12245?
To fix CVE-2025-12245, update the Chatwoot Widget to version 4.7.1 or later.
What component is affected by CVE-2025-12245?
CVE-2025-12245 specifically affects the Widget component in the Chatwoot application.
What is the nature of the vulnerability in CVE-2025-12245?
CVE-2025-12245 involves an origin validation error due to improper handling of the baseUrl argument.
Can CVE-2025-12245 lead to unauthorized access?
Yes, CVE-2025-12245 can potentially lead to unauthorized access and exploitation by remote attackers.