CVE-2023-47215: XSS
Published Dec 26, 2023
·Updated
Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
Affected Software
1 affected component
WESEEK GROWI<6.0.0
Event History
Dec 26, 2023
CVE Published
07:20 AM
Data Sourced
07:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47215?
The severity of CVE-2023-47215 is classified as medium due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2023-47215?
To mitigate CVE-2023-47215, upgrade GROWI to version 6.0.0 or later.
3
What software does CVE-2023-47215 affect?
CVE-2023-47215 affects GROWI versions prior to v6.0.0.
4
What type of vulnerability is CVE-2023-47215?
CVE-2023-47215 is a stored cross-site scripting vulnerability.
5
How can CVE-2023-47215 be exploited?
CVE-2023-47215 can be exploited by executing arbitrary scripts in the web browser of users accessing the affected site.