Published: 2021/03/10  Last Updated: 2021/03/10

Information from WESEEK, Inc.

Vulnerability ID:JVN#86438134
Title:Multiple cross-site scripting vulnerabilities in GROWI
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

[Summary]
GROWI is developed by WESEEK, Inc.
GROWI releases prior to v4.2.8 contain some bugs that cause risks that can be exploited to perform cross-site scripting attacks.


[Affected Products]
This bug affects GROWI from v4.2.0 to v4.2.7 (v4.2 Series)

[Description]
GROWI releases prior to v4.2.8 contain some bugs that can be exploited to perform cross-site scripting attacks.

[Impact]
An attacker can execute potentially malicious script code on the website visitor's browser.

[Solution]
Please upgrade your GROWI to v4.2.8 or later.

### Where to get the updated version
- [GitHub](https://github.com/weseek/growi)
- [Docker Hub](https://hub.docker.com/r/weseek/growi/)