PT-2019-13274 · Weseek · Growi

Olle Westrin

·

Publicado

2019-07-09

·

Atualizado

2021-07-21

·

CVE-2019-13338

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WESEEK GROWI versions prior to 3.5.0
Description A remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. The password hash can be retrieved even though it is not a publicly available field.
Recommendations For versions prior to 3.5.0, update to version 3.5.0 or later to resolve the issue.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13338

Produtos afetados

Growi