Vulnerability Database

318,638

Total vulnerabilities in the database

CVE-2021-3740

A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token.

  • Published: Nov 15, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-3740
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.8
  • AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H