NA

CVE-2023-46699

Published: 26/12/2023 Updated: 04/01/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settings may be changed without the user's intention.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

weseek growi