CVE-2023-45737: XSS
Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45737?
CVE-2023-45737 is categorized as a stored cross-site scripting vulnerability that can lead to significant security risks for the affected application.
How do I fix CVE-2023-45737?
To fix CVE-2023-45737, upgrade GROWI to version 3.5.0 or later, as it includes a patch for this vulnerability.
What versions of GROWI are affected by CVE-2023-45737?
CVE-2023-45737 affects all versions of GROWI prior to v3.5.0.
What does CVE-2023-45737 allow an attacker to do?
CVE-2023-45737 allows an attacker to execute arbitrary scripts in the web browser of users accessing the affected GROWI application.
Where is the vulnerability located in GROWI according to CVE-2023-45737?
The vulnerability exists in the App Settings and Markdown Settings pages of GROWI.