Medium severity4.8NVD Advisory· Published Mar 10, 2021· Updated Jun 17, 2026
CVE-2021-20673
CVE-2021-20673
Description
Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WESEEK, Inc./GROWI (v4.2 Series)v5Range: versions from v4.2.0 to v4.2.7
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN86438134/index.htmlnvdThird Party Advisory
- weseek.co.jp/security/2021/03/09/vulnerability/growi-prevent-xss5/nvdVendor Advisory
News mentions
0No linked articles in our index yet.