CVE-2020-5683: Path Traversal
Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to alter the data by uploading a specially crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5683?
CVE-2020-5683 is classified as a high severity directory traversal vulnerability.
How do I fix CVE-2020-5683?
To fix CVE-2020-5683, upgrade to GROWI version 4.2.3 or later for the v4.2 series or 4.1.12 or later for the v4.1 series.
What types of attacks can CVE-2020-5683 facilitate?
CVE-2020-5683 can facilitate unauthorized access to restricted files on the server through directory traversal attacks.
Which versions are affected by CVE-2020-5683?
CVE-2020-5683 affects GROWI versions prior to 4.2.3, 4.1.12, and all versions of GROWI v3 and earlier.
Who is impacted by CVE-2020-5683?
Organizations using the affected versions of GROWI could be impacted by CVE-2020-5683 if they do not apply the necessary updates.