Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://growi.co.jp/news/40/ |
|
| https://jvn.jp/en/jp/JVN55745775/ |
|
History
Wed, 17 Dec 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations. | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-12-17T04:06:08.388Z
Reserved: 2025-11-10T08:39:24.724Z
Link: CVE-2025-64700
No data.
Status : Received
Published: 2025-12-17T05:16:13.447
Modified: 2025-12-17T05:16:13.447
Link: CVE-2025-64700
No data.
OpenCVE Enrichment
No data.
Weaknesses