CVE-2020-5677: XSS
Published Dec 3, 2020
·Updated
Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
Affected Software
1 affected component
WESEEK GROWI<=4.0.0
Event History
Dec 3, 2020
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5677?
The severity of CVE-2020-5677 is considered medium due to the potential for remote code execution via reflected cross-site scripting.
2
How do I fix CVE-2020-5677?
To fix CVE-2020-5677, upgrade GROWI to version 4.0.1 or later where the vulnerability has been addressed.
3
What types of attacks does CVE-2020-5677 allow?
CVE-2020-5677 allows remote attackers to inject arbitrary scripts into web pages, potentially leading to unauthorized data access.
4
Which versions of GROWI are affected by CVE-2020-5677?
GROWI versions up to and including 4.0.0 are affected by CVE-2020-5677.
5
Is user input a factor in CVE-2020-5677?
Yes, CVE-2020-5677 exploits unvalidated user input fields, enabling attackers to execute scripts.