Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://growi.co.jp/news/39/ |
|
| https://jvn.jp/en/jp/JVN95942191/ |
|
History
Thu, 06 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Growi
Growi growi |
|
| Vendors & Products |
Growi
Growi growi |
Thu, 06 Nov 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-11-06T04:14:30.106Z
Updated: 2025-11-06T14:09:38.630Z
Reserved: 2025-10-29T08:38:11.617Z
Link: CVE-2025-61994
Updated: 2025-11-06T14:09:35.939Z
Status : Awaiting Analysis
Published: 2025-11-06T05:16:09.407
Modified: 2025-11-06T19:45:09.883
Link: CVE-2025-61994
No data.