CVE-2021-3741
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2021-3741 is a stored cross-site scripting (XSS) vulnerability affecting the chatwoot/chatwoot application before version 2.6. This issue allows an attacker to upload an SVG file with a malicious XSS payload in the profile settings. When a user opens the avatar in a new page, the custom JavaScript code contained within the file is executed, potentially exposing the user to security risks. This vulnerability can lead to unintended execution of malicious code in the context of the affected user, making it a significant security concern. All users are advised to upgrade to the latest version of chatwoot/chatwoot to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Zohocorp ManageEngine ServiceDesk Plus
- ManageEngine ServiceDesk Plus
Affected Vendors
- Manage Engine
- Zoho Corporation