CVE-2019-13338: Weseek Growi
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.
Affected products
- Weseek Growi: before 3.5.0 (fixed in 3.5.0)
Published 2019-07-09. Last modified 2026-06-17.