In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.5.0"
}
],
"cpes": [
"cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "weseek:growi"
}
]
}