CVE-2021-20736: SQL Injection
Published Jun 22, 2021
·Updated
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
Affected Software
1 affected component
WESEEK GROWI<4.2.20
Event History
Jun 22, 2021
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20736?
CVE-2021-20736 is classified as a critical NoSQL injection vulnerability.
2
How do I fix CVE-2021-20736?
To mitigate CVE-2021-20736, upgrade GROWI to version 4.2.20 or later.
3
What versions of GROWI are affected by CVE-2021-20736?
GROWI versions prior to v4.2.20 are affected by CVE-2021-20736.
4
What type of attack does CVE-2021-20736 enable?
CVE-2021-20736 allows a remote attacker to obtain and alter the information stored in the database.
5
What are the potential impacts of CVE-2021-20736?
Exploitation of CVE-2021-20736 can lead to unauthorized access and manipulation of database information.