Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://growi.co.jp/news/39/ |
|
| https://jvn.jp/en/jp/JVN95942191/ |
|
History
Thu, 06 Nov 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-11-06T04:14:30.106Z
Reserved: 2025-10-29T08:38:11.617Z
Link: CVE-2025-61994
No data.
Status : Received
Published: 2025-11-06T05:16:09.407
Modified: 2025-11-06T05:16:09.407
Link: CVE-2025-61994
No data.
OpenCVE Enrichment
No data.