ZeroHour

CVE-2019-13337

CVSS 3.0
7.5 high
EPSS
1%p71
Published
()
Modified
Description

In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic authentication is required.

Vendors
weseek
Products
growi
Weakness
CWE-639, CWE-863
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.