Weseek

Growi

42 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Published 03.12.2020 12:15:11
  • Last modified 21.11.2024 05:34:27

GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.

  • EPSS 0.42%
  • Published 03.12.2020 12:15:11
  • Last modified 21.11.2024 05:34:27

Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

  • EPSS 0.34%
  • Published 09.07.2019 20:15:10
  • Last modified 21.11.2024 04:24:44

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly a...

  • EPSS 0.23%
  • Published 09.07.2019 20:15:10
  • Last modified 21.11.2024 04:24:44

In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then...

  • EPSS 0.22%
  • Published 05.07.2019 14:15:12
  • Last modified 21.11.2024 04:45:49

Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.

  • EPSS 0.17%
  • Published 05.07.2019 14:15:12
  • Last modified 21.11.2024 04:45:49

Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.

  • EPSS 0.17%
  • Published 09.01.2019 23:29:05
  • Last modified 21.11.2024 03:52:17

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.

  • EPSS 0.15%
  • Published 09.01.2019 23:29:02
  • Last modified 21.11.2024 03:38:46

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.18%
  • Published 07.09.2018 14:29:02
  • Last modified 21.11.2024 03:38:40

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the app settings section of admin page.

  • EPSS 0.23%
  • Published 07.09.2018 14:29:02
  • Last modified 21.11.2024 03:38:40

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for creating Wiki page.