VYPR
Medium severity4.8NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-0640

CVE-2024-0640

Description

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another admin user when they access the affected dashboard app. The issue is fixed in version 3.5.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Chatwoot/Chatwoot3 versions
    cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*range: <3.5.2
    • (no CPE)range: <3.5.2
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.