Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 27 Oct 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin Interface. The manipulation of the argument Link results in cross site scripting. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | chatwoot Admin IframeLoader.vue cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-27T07:32:09.692Z
Reserved: 2025-10-26T05:12:08.424Z
Link: CVE-2025-12246
No data.
Status : Received
Published: 2025-10-27T08:15:37.153
Modified: 2025-10-27T08:15:37.153
Link: CVE-2025-12246
No data.
OpenCVE Enrichment
No data.