Unrated severityNVD Advisory· Published Mar 10, 2021· Updated Aug 3, 2024
CVE-2021-20671
CVE-2021-20671
Description
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/vu/JVNVU94889258/index.htmlmitrex_refsource_MISC
- weseek.co.jp/security/2021/03/08/vulnerability/growi-prevent-multiple-xss/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.