Vulnerabilites related to WESEEK, Inc. - GROWI v4.2 Series
CVE-2021-20619 (GCVE-0-2021-20619)
Vulnerability from cvelistv5
Published
2021-01-19 04:55
Modified
2024-08-03 17:45
Severity ?
CWE
  • Cross-site scripting
Summary
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.
Impacted products
Vendor Product Version
WESEEK, Inc. GROWI v4.2 Series Version: versions prior to v4.2.3
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T17:45:44.833Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://github.com/weseek/growi"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://weseek.co.jp/security/2021/01/18/vulnerability/growi-prevent-xss4/"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN57544707/index.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "GROWI v4.2 Series",
          "vendor": "WESEEK, Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "versions prior to v4.2.3"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-site scripting",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2021-01-19T04:55:16",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/weseek/growi"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://weseek.co.jp/security/2021/01/18/vulnerability/growi-prevent-xss4/"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://jvn.jp/en/jp/JVN57544707/index.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2021-20619",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "GROWI v4.2 Series",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "versions prior to v4.2.3"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "WESEEK, Inc."
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Cross-site scripting"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://github.com/weseek/growi",
              "refsource": "MISC",
              "url": "https://github.com/weseek/growi"
            },
            {
              "name": "https://weseek.co.jp/security/2021/01/18/vulnerability/growi-prevent-xss4/",
              "refsource": "MISC",
              "url": "https://weseek.co.jp/security/2021/01/18/vulnerability/growi-prevent-xss4/"
            },
            {
              "name": "https://jvn.jp/en/jp/JVN57544707/index.html",
              "refsource": "MISC",
              "url": "https://jvn.jp/en/jp/JVN57544707/index.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2021-20619",
    "datePublished": "2021-01-19T04:55:16",
    "dateReserved": "2020-12-17T00:00:00",
    "dateUpdated": "2024-08-03T17:45:44.833Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}