PT-2021-14274 · Growi · Growi

Published

2021-09-21

·

Updated

2021-09-29

·

CVE-2021-20829

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: GROWI versions v4.2.19 and earlier
Description: The issue is due to inadequate tag sanitization, allowing remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page. This enables the execution of arbitrary scripts, potentially leading to unauthorized actions.
Recommendations: For GROWI versions v4.2.19 and earlier, update to a version later than v4.2.19 to resolve the issue. As a temporary workaround, consider implementing additional tag sanitization measures to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20829

Affected Products

Growi