CVE-2023-50332: Medium severity growi vulnerability
Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50332?
CVE-2023-50332 has been classified as a high severity vulnerability due to the potential for unauthorized account deletion or suspension.
How do I fix CVE-2023-50332?
To fix CVE-2023-50332, upgrade GROWI to version 6.0.6 or later to eliminate the improper authorization vulnerability.
Which versions of GROWI are affected by CVE-2023-50332?
GROWI versions prior to v6.0.6 are affected by CVE-2023-50332.
What can an attacker do if CVE-2023-50332 is exploited?
If CVE-2023-50332 is exploited, an attacker can delete or suspend their own account, leading to potential disruption.
Is there a workaround for CVE-2023-50332?
Currently, the best course of action for CVE-2023-50332 is to apply the available update to mitigate the risk.