CVE-2023-46699: CSRF
Published Dec 26, 2023
·Updated
Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settings may be changed without the user's intention.
Affected Software
1 affected component
WESEEK GROWI<6.0.0
Event History
Dec 26, 2023
CVE Published
07:20 AM
Data Sourced
07:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46699?
CVE-2023-46699 is rated as a high severity vulnerability due to the potential for unauthorized changes in user settings.
2
How do I fix CVE-2023-46699?
To fix CVE-2023-46699, update your GROWI installation to version 6.0.0 or later.
3
What types of attacks are possible with CVE-2023-46699?
CVE-2023-46699 allows for cross-site request forgery attacks that can change user settings without their consent.
4
Who is affected by CVE-2023-46699?
Users of GROWI versions prior to v6.0.0 are affected by CVE-2023-46699.
5
What should I do if I cannot update to fix CVE-2023-46699?
If you cannot update, ensure your users are aware of the risks and avoid visiting potentially malicious links while logged into GROWI.