CVE-2023-50294
26.12.2023, 08:15
The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.Enginsight
Vendor | Product | Version |
---|---|---|
weseek | growi | 𝑥 < 6.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration