CVE-2021-20670

Improper Access Control leading to Information Leakage in GROWI

GROWI におけるアクセス制限の不備

Improper access control of files allows an unauthenticated remote attacker to read the user's personal information and/or server's internal information

Disclosure Date

2021/03/08

Credit

stypr (@stereotype32)

CWE

  • CWE-284

Product URLs

Reference