CVE-2021-20672

Source
https://cve.org/CVERecord?id=CVE-2021-20672
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20672.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-20672
Published
2021-03-10T10:15:12.957Z
Modified
2026-04-10T04:29:23.696530Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote attackers to inject an arbitrary script via unspecified vectors.

References

Affected packages

Git / github.com/weseek/growi

Affected ranges

Type
GIT
Repo
https://github.com/weseek/growi
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.2.0"
        },
        {
            "last_affected": "4.2.7"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20672.json"