Published: 2018/08/03  Last Updated: 2018/08/03

Information from WESEEK, Inc.

Vulnerability ID:JVN#18716340
Title:Multiple cross-site scripting vulnerabilities in GROWI

This is a statement from the vendor itself with no modification by JPCERT/CC.

GROWI is developed by WESEEK, Inc.
GROWI releases prior to v3.1.1 contains a cross-site scripting(XSS) vulnerability which can be exploited to perform cross-site scripting attacks.

[Affected Products]
This vulnerability affects GROWI releases prior to v3.1.1

GROWI releases prior to v3.1.1 contain a cross-site scripting(XSS) vulnerability.

An attacker can execute potentially malicious script code on website visitor's browser.

To fix this vulnerability, upgrade to v3.1.12 or later provideded by the developer.