CVE-2019-13337: High severity growi vulnerability
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter accesstoken (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic authentication is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13337?
CVE-2019-13337 has a medium severity level due to the bypass of site-wide basic authentication.
How can I fix CVE-2019-13337?
To fix CVE-2019-13337, upgrade WESEEK GROWI to version 3.5.0 or later where the vulnerability is addressed.
What impact does CVE-2019-13337 have on my systems?
CVE-2019-13337 allows unauthorized users to access the site and bypass basic authentication without a valid access token.
Which versions of WESEEK GROWI are affected by CVE-2019-13337?
WESEEK GROWI versions prior to 3.5.0 are affected by CVE-2019-13337.
Is CVE-2019-13337 a local or remote vulnerability?
CVE-2019-13337 is considered a remote vulnerability as it can be exploited without local access to the system.