CVE-2020-5676
- EPSS 0.57%
- Published 03.12.2020 12:15:11
- Last modified 21.11.2024 05:34:27
GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.
CVE-2020-5678
- EPSS 0.42%
- Published 03.12.2020 12:15:11
- Last modified 21.11.2024 05:34:27
Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
CVE-2019-13338
- EPSS 0.34%
- Published 09.07.2019 20:15:10
- Last modified 21.11.2024 04:24:44
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly a...
CVE-2019-13337
- EPSS 0.23%
- Published 09.07.2019 20:15:10
- Last modified 21.11.2024 04:24:44
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then...
CVE-2019-5969
- EPSS 0.22%
- Published 05.07.2019 14:15:12
- Last modified 21.11.2024 04:45:49
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
CVE-2019-5968
- EPSS 0.17%
- Published 05.07.2019 14:15:12
- Last modified 21.11.2024 04:45:49
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
CVE-2018-16205
- EPSS 0.17%
- Published 09.01.2019 23:29:05
- Last modified 21.11.2024 03:52:17
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.
CVE-2018-0698
- EPSS 0.15%
- Published 09.01.2019 23:29:02
- Last modified 21.11.2024 03:38:46
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0655
- EPSS 0.18%
- Published 07.09.2018 14:29:02
- Last modified 21.11.2024 03:38:40
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the app settings section of admin page.
CVE-2018-0654
- EPSS 0.23%
- Published 07.09.2018 14:29:02
- Last modified 21.11.2024 03:38:40
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for creating Wiki page.