CVE-2019-5968: Weseek Growi
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
Affected products
- Weseek Growi: up to and including 3.4.6
Published 2019-07-05. Last modified 2026-06-17.