CVE-2025-21628 | Chatwoot up to 3.15.x API query_operator sql injection (GHSA-g8f9-hh83-rcq9)
A vulnerability, which was classified as critical, was found in Chatwoot up to 3.15.x. This impacts the function query_operator of the component API. Executing manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2025-21628. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.