CVE-2021-3742
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Nov 15, 2024
CWE ID 611
Summary
CVE-2021-3742 is a Server-Side Request Forgery (SSRF) vulnerability affecting the chatwoot/chatwoot software, impacting all versions below 2.5.0. An attacker can exploit this issue by uploading a malicious SVG file as an avatar. Once opened in a new tab, the file triggers the SSRF, potentially redirecting the host to an attacker's server. This vulnerability poses a significant risk, as it can lead to unauthorized access and data exposure. To mitigate this risk, users are advised to update their chatwoot installation to the latest stable version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.