Published: 2018/08/03  Last Updated: 2018/08/03

Information from WESEEK, Inc.

Vulnerability ID:JVN#18716340
Title:Multiple cross-site scripting vulnerabilities in GROWI

GROWI is developed by WESEEK, Inc.
GROWI releases prior to v3.1.1 contains a cross-site scripting(XSS) vulnerability which can be exploited to perform cross-site scripting attacks.

[Affected Products]
This vulnerability affects GROWI releases prior to v3.1.1

An attacker can execute potentially malicious script code on website visitor's browser.

To fix this vulnerability, upgrade to v3.1.12 or later provideded by the developer.