CVE-2019-13338

CVE-2019-13338

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.

Source: CVE-2019-13338

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다