CVE-2021-20673: XSS
Published Mar 10, 2021
·Updated
Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
Affected Software
1 affected component
WESEEK GROWI>=4.2.0<=4.2.7
Event History
Mar 10, 2021
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20673?
The severity of CVE-2021-20673 is rated as medium with a CVSS score of 4.8.
2
How can I exploit the stored cross-site scripting vulnerability in GROWI Admin Page (v4.2 Series)?
Remote authenticated attackers can exploit the vulnerability by injecting arbitrary scripts through unspecified vectors.
3
What software versions are affected by CVE-2021-20673?
The stored cross-site scripting vulnerability affects GROWI v4.2.0 to v4.2.7 in the v4.2 Series.
4
What is the CWE ID associated with CVE-2021-20673?
CVE-2021-20673 is associated with CWE ID 79, which is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
Where can I find more information about CVE-2021-20673?
You can find more information about CVE-2021-20673 on the Japan Vulnerability Notes (JVN) and WESEEK websites.