CVE-2021-20671: Input Validation
Published Mar 10, 2021
·Updated
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.
Affected Software
1 affected component
WESEEK GROWI=4.2.2
Event History
Mar 10, 2021
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20671?
CVE-2021-20671 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2021-20671?
To fix CVE-2021-20671, upgrade to a version of GROWI that is later than v4.2.2.
3
Who is affected by CVE-2021-20671?
CVE-2021-20671 affects GROWI version v4.2.2 users who have administrative privileges.
4
What is the impact of CVE-2021-20671?
CVS-2021-20671 can lead to compromising server integrity through file overwriting and arbitrary code execution.
5
Is there a workaround for CVE-2021-20671?
There is no public workaround for CVE-2021-20671; the recommended action is to upgrade to a secure version.