CVE-2021-20668: Path Traversal
Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20668?
CVE-2021-20668 is categorized as a high severity vulnerability due to its potential impact on system security involving path traversal.
How do I fix CVE-2021-20668?
To fix CVE-2021-20668, update the GROWI application to version 4.2.3 or later, which addresses this vulnerability.
Who is affected by CVE-2021-20668?
CVE-2021-20668 affects all GROWI versions up to and including v4.2.2, specifically those where an attacker has administrator rights.
What type of vulnerability is CVE-2021-20668?
CVE-2021-20668 is a path traversal vulnerability that allows unauthorized access to files based on crafted URLs.
Can CVE-2021-20668 allow remote code execution?
CVE-2021-20668 does not directly allow remote code execution, but it does enable access to arbitrary files, which could lead to further exploitation.