cvedb.io
CVE-2022-3741
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2022-10-28T13:15:16.870 · Last modified 2026-06-17T05:00:12.763

Summary

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.

Affected products

chatwoot — chatwoot

Does this affect you?

Add your gear to cvedb and we'll alert you only when chatwoot ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.