GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Oct 2025 04:30:00 +0000

Type Values Removed Values Added
Description GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-10-23T04:10:59.281Z

Reserved: 2025-10-15T05:16:42.225Z

Link: CVE-2025-54806

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-23T05:15:32.403

Modified: 2025-10-23T05:15:32.403

Link: CVE-2025-54806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.