Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
Vulnerability Description
Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
CWE-915
Vulnerability Title
Chatwoot 输入验证错误漏洞
Vulnerability Description
Chatwoot是Chatwoot组织开源的一款多渠道客服支持平台。 Chatwoot 4.9.0之前版本存在输入验证错误漏洞,该漏洞源于通过可写的account_id参数将Portals、Automation Rules、Macros和Twilio Channels转移到其他账户,破坏租户隔离,可能导致跨账户数据暴露、未经授权的配置更改或丢失对转移资源的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A