CVE-2021-20672 Vulnerability Details

  /     /     /  

CVE-2021-20672 Metadata Quick Info

CVE Published: 10/03/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: jpcert | Vendor: WESEEK, Inc. | Product: GROWI (v4.2 Series)
Status : PUBLISHED

CVE-2021-20672 Description

Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote attackers to inject an arbitrary script via unspecified vectors.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Cross-site scripting
Source: WESEEK, Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).