Impact
An improper access control flaw exists in GROWI that allows an unauthenticated attacker to read files stored in non-public pages when the file upload configuration is set to Local. The flaw enables data disclosure of potentially sensitive documents and configuration files. This is a classic file-system read vulnerability classified as CWE-552, which can compromise the confidentiality of information stored by the application, but does not grant code execution or tampering capabilities.
Affected Systems
The vulnerability affects all installations of GROWI Inc.'s GROWI platform. The affected product is identified as GROWI. There is no specific version range provided; the flaw applies to any deployment where the file upload setting uses local storage. Administrators should verify which version they are running and whether the local upload option is enabled.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact, combined with an unknown EPSS score because the exploit probability data is not available. Since the vulnerability is not listed in the CISA KEV catalog, there is no current evidence of active exploitation. The likely attack vector is a web-based request to a non-public page that contains uploaded files. An attacker does not need authentication to trigger the file read, so the risk to systems with accessible web interfaces is high if the file upload setting remains on Local. Proper remediation drastically reduces exploitation risk.
OpenCVE Enrichment