Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwvv-h48v-hrrm

Опубликовано: 31 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.

EPSS

Процентиль: 22%
0.00289
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.3
nvd
19 дней назад

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.

EPSS

Процентиль: 22%
0.00289
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-639