GHSA-xwvv-h48v-hrrmMediumCVSS 6.3

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the...

Published
August 31, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (1)

📋 Description

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.

🔗 References (4)