PT-2021-14274 · Growi · Growi
Published
2021-09-21
·
Updated
2021-09-29
·
CVE-2021-20829
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
GROWI versions v4.2.19 and earlier
Description:
The issue is due to inadequate tag sanitization, allowing remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page. This enables the execution of arbitrary scripts, potentially leading to unauthorized actions.
Recommendations:
For GROWI versions v4.2.19 and earlier, update to a version later than v4.2.19 to resolve the issue. As a temporary workaround, consider implementing additional tag sanitization measures to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Growi