### [CVE-2021-3740](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3740) ![](https://img.shields.io/static/v1?label=Product&message=chatwoot%2Fchatwoot&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-384%20Session%20Fixation&color=brightgreen) ### Description A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ajmalabubakkr/CVE