CVE-2021-20829 Vulnerability Details

  /     /     /  

CVE-2021-20829 Metadata Quick Info

CVE Published: 21/09/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: jpcert | Vendor: WESEEK, Inc. | Product: GROWI
Status : PUBLISHED

CVE-2021-20829 Description

Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Cross-site scripting
Source: WESEEK, Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).