CVE-2023-45737

Source
https://cve.org/CVERecord?id=CVE-2023-45737
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-45737.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-45737
Published
2023-12-26T07:20:36Z
Modified
2026-08-27T03:57:01Z
Summary
[none]
Details

Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

Database specific
{
    "cna_assigner": "jpcert",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45737.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "prior to v3.5.0"
                },
                {
                    "last_affected": "prior to v3.5.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/growilabs/growi

Affected ranges

Type
GIT
Repo
https://github.com/growilabs/growi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.5.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

1.*
1.0.0-RC3
v1.*
v1.0.0-RC
v1.0.0-RC2
v1.0.0-RC4
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-45737.json"