chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 71% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
n/a · chatwootPoCs públicas encontradas — 1
cve_referencegithub.com/chatwoot/chatwoot/issues/14887no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/chatwoot/chatwoot/https://github.com/chatwoot/chatwoot/issues/14887https://github.com/chatwoot/chatwoot/security/advisories/GHSA-wxhm-4rjw-9m7vhttps://vuldb.com/cve/CVE-2026-92527https://vuldb.com/submit/941600https://vuldb.com/vuln/405756https://vuldb.com/vuln/405756/cti