CVE-2021-3813
09.02.2022, 15:15
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.Enginsight
Vendor | Product | Version |
---|---|---|
chatwoot | chatwoot | 𝑥 ≤ 2.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References