CVE 6.9 MEDIUM

chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation_CVE-2025-12245

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-12245
Source VulDB
Published Oct 27, 2025 at 07:32

Affected Product

Vendor n/a
Product chatwoot
Version 4.0
Affected Versions n/a chatwoot 4.0
n/a chatwoot 4.1
n/a chatwoot 4.2
n/a chatwoot 4.3
n/a chatwoot 4.4
n/a chatwoot 4.5
n/a chatwoot 4.6
n/a chatwoot 4.7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.