CVE Published: 10/03/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jpcert |
Vendor: WESEEK, Inc. |
Product: GROWI Status : PUBLISHED
CVE-2021-20671 Description
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.