GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Weseek
Weseek growi
CPEs cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*
Vendors & Products Weseek
Weseek growi
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Growi
Growi growi
Vendors & Products Growi
Growi growi

Thu, 23 Oct 2025 04:30:00 +0000

Type Values Removed Values Added
Description GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-10-23T15:05:14.336Z

Reserved: 2025-10-15T05:16:42.225Z

Link: CVE-2025-54806

cve-icon Vulnrichment

Updated: 2025-10-23T15:04:07.622Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-23T05:15:32.403

Modified: 2025-11-12T17:26:58.823

Link: CVE-2025-54806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-23T09:58:35Z