CVE-2021-3852

No Score
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

growi is vulnerable to Authorization Bypass Through User-Controlled Key

References

https://huntr.dev/bounties/d44def81-2834-4031-9037-e923975c3852

https://github.com/weseek/growi/commit/863bfd7f622f413bd159b9446166fb1ce78ec863

Details

Source: MITRE

Published: 2022-01-12

Updated: 2022-01-12

Type: CWE-639