PT-2026-84302 · Growi · Growi
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GROWI versions prior to 8.0.2
Description
An access control issue exists where the system fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they are not authorized to view by providing known attachment identifiers to the 'GET / api/v3/attachment/:id' endpoint.
Recommendations
Update GROWI to version 8.0.2 or later.
Restrict access to the 'GET / api/v3/attachment/:id' endpoint to minimize the risk of unauthorized metadata retrieval.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Growi