6.5
CVE-2022-41799
- EPSS 0.8%
- Veröffentlicht 24.10.2022 14:15:52
- Zuletzt bearbeitet 07.05.2025 17:15:57
- CVE-Watchlists
- Unerledigt
Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.8% | 0.532 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
https://jvn.jp/en/jp/JVN00845253/index.html
https://weseek.co.jp/en/news/2022/10/07/growi-private-page-can-be-viewed/