CVE-2019-13338: High severity growi vulnerability
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13338?
CVE-2019-13338 has been classified as a high severity vulnerability due to the potential for a remote attacker to obtain sensitive password hashes.
How do I fix CVE-2019-13338?
To fix CVE-2019-13338, upgrade WESEEK GROWI to version 3.5.0 or later.
Who is affected by CVE-2019-13338?
Users running WESEEK GROWI versions prior to 3.5.0 are affected by CVE-2019-13338.
What is the impact of CVE-2019-13338?
The impact of CVE-2019-13338 is that remote attackers can retrieve the password hash of page creators, potentially compromising account security.
Can CVE-2019-13338 be exploited without authentication?
Yes, CVE-2019-13338 can be exploited by an unauthenticated remote attacker with access to the wiki.