CVE-2021-20619: XSS
Published Jan 19, 2021
·Updated
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.
Affected Software
1 affected component
WESEEK GROWI>=4.2.0<4.2.3
Event History
Jan 19, 2021
CVE Published
via MITRE·04:55 AM
Data Sourced
via MITRE·04:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20619?
CVE-2021-20619 has a moderate severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2021-20619?
To mitigate CVE-2021-20619, upgrade GROWI to version 4.2.3 or later.
3
What versions of GROWI are affected by CVE-2021-20619?
CVE-2021-20619 affects GROWI versions from 4.2.0 up to, but not including, 4.2.3.
4
Can CVE-2021-20619 lead to data exposure?
Yes, CVE-2021-20619 can potentially allow attackers to inject scripts that expose sensitive user data.
5
Is user input a vector for CVE-2021-20619?
Yes, user input may be one of the unspecified vectors used to exploit CVE-2021-20619.