CVE-2024-0640

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-0640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-0640
Published
2025-03-20T10:15:14Z
Modified
2025-03-21T01:49:58.437788Z
Summary
[none]
Details

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another admin user when they access the affected dashboard app. The issue is fixed in version 3.5.2.

References

Affected packages

Git / github.com/chatwoot/chatwoot

Affected ranges

Type
GIT
Repo
https://github.com/chatwoot/chatwoot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.2.4
1.4.2

2.*

2.16.1

v0.*

v0.1.0

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.11.0
v1.11.1
v1.12.0
v1.12.1
v1.12.2
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.15.0
v1.15.1
v1.16.1
v1.16.2
v1.17.0
v1.17.1
v1.18.0
v1.18.1
v1.18.2
v1.19.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.20.0
v1.21.0
v1.21.1
v1.22.0
v1.22.1
v1.3.0
v1.4.0
v1.4.1
v1.4.2
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.9.0

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.13.0
v2.13.1
v2.14.0
v2.15.0
v2.16.0
v2.17.0
v2.17.1
v2.18.0
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.3.2
v2.4.0
v2.4.1
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1

v3.*

v3.0.0
v3.0.0-rc1
v3.1.0
v3.1.1