CVE-2021-20669: Path Traversal
Published Mar 10, 2021
·Updated
Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read and/or delete an arbitrary path via a specially crafted URL.
Affected Software
1 affected component
WESEEK GROWI<=4.2.2
Event History
Mar 10, 2021
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20669?
CVE-2021-20669 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive files.
2
How do I fix CVE-2021-20669?
To fix CVE-2021-20669, upgrade GROWI to version 4.2.3 or later.
3
Who is affected by CVE-2021-20669?
CVE-2021-20669 affects GROWI versions v4.2.2 and earlier, particularly those instances where administrators have rights.
4
What type of attack does CVE-2021-20669 enable?
CVE-2021-20669 enables a path traversal attack that allows reading or deleting files on the server.
5
Can CVE-2021-20669 be exploited remotely?
Yes, CVE-2021-20669 can be exploited remotely through specially crafted URLs.