CVE-2021-20667: XSS
Published Mar 10, 2021
·Updated
Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier allows remote authenticated attackers to inject an arbitrary script via a specially crafted content.
Affected Software
1 affected component
WESEEK GROWI<=4.2.2
Event History
Mar 10, 2021
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20667?
CVE-2021-20667 is a stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier.
2
How does CVE-2021-20667 impact GROWI software?
CVE-2021-20667 allows remote authenticated attackers to inject an arbitrary script via specially crafted content.
3
What is the severity level of CVE-2021-20667?
CVE-2021-20667 has a severity level of 5.4, classified as medium.
4
How can I prevent the Stored XSS in GROWI versions v4.2.2 and earlier?
To prevent the Stored XSS vulnerability in GROWI versions v4.2.2 and earlier, update the CSP (Content Security Policy) configuration to adequately mitigate the risk.