A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:* |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatwoot
Chatwoot chatwoot |
|
| Vendors & Products |
Chatwoot
Chatwoot chatwoot |
Mon, 27 Oct 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation | |
| Weaknesses | CWE-345 CWE-346 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-27T07:32:07.544Z
Updated: 2025-10-27T18:25:56.142Z
Reserved: 2025-10-26T05:12:01.062Z
Link: CVE-2025-12245
No data.
Status : Analyzed
Published: 2025-10-27T08:15:36.950
Modified: 2025-10-28T02:15:11.223
Link: CVE-2025-12245
No data.