CVE-2022-41799

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/10/2022
Last modified:
07/05/2025

Description

Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:* 4.0.0 (including) 4.5.25 (excluding)
cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:* 5.0.0 (including) 5.1.4 (excluding)