CVE-2025-64700: CSRF
Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64700?
CVE-2025-64700 is classified as a high severity vulnerability due to its potential to execute unintended operations on behalf of authenticated users.
How do I fix CVE-2025-64700?
To fix CVE-2025-64700, upgrade GROWI to version 7.3.4 or later, which addresses this cross-site request forgery vulnerability.
What applications are affected by CVE-2025-64700?
CVE-2025-64700 affects GROWI versions 7.3.3 and earlier.
What kind of attack does CVE-2025-64700 facilitate?
CVE-2025-64700 facilitates cross-site request forgery (CSRF) attacks, allowing attackers to perform actions without user consent.
How does CVE-2025-64700 impact user security?
CVE-2025-64700 can compromise user security by allowing malicious pages to make unauthorized requests on behalf of an authenticated user.