CVE-2021-20737: Medium severity growi vulnerability
Published Jun 22, 2021
·Updated
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
Affected Software
1 affected component
WESEEK GROWI<4.2.20
Event History
Jun 22, 2021
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20737?
CVE-2021-20737 is classified as a moderate severity vulnerability due to the potential for unauthorized access to sensitive pages.
2
How do I fix CVE-2021-20737?
To remediate CVE-2021-20737, update GROWI to version 4.2.20 or later.
3
What software versions are affected by CVE-2021-20737?
CVE-2021-20737 affects GROWI versions prior to v4.2.20.
4
What type of vulnerability is CVE-2021-20737?
CVE-2021-20737 is an improper authentication vulnerability.
5
Can a remote attacker exploit CVE-2021-20737?
Yes, a remote attacker can exploit CVE-2021-20737 to view unauthorized pages without proper access privileges.