CVE-2023-50332: Weseek Growi
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention.
Affected products
- Weseek Growi: before 6.0.6 (fixed in 6.0.6)
Published 2023-12-26. Last modified 2026-06-17.