CVE-2021-20672
Summary
| CVE | CVE-2021-20672 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-10 10:15:00 UTC |
| Updated | 2021-03-16 19:26:00 UTC |
| Description | Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote attackers to inject an arbitrary script via unspecified vectors. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#86438134: Multiple cross-site scripting vulnerabilities in GROWI | MISC | jvn.jp | Third Party Advisory |
| GROWI 脆弱性対応のお知らせ (JVN#86438134) | WESEEK, Inc. | MISC | weseek.co.jp | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.