Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-50175
HistoryDec 26, 2023 - 8:15 a.m.

Cross site scripting

2023-12-2608:15:00
PRIOn knowledge base
www.prio-n.com
3
cross-site scripting
growi
vulnerability
arbitrary script
web browser
exploited

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/markdown) page, and the Customize (/admin/customize) page of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

CPENameOperatorVersion
growilt6.0.0

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Related for PRION:CVE-2023-50175