CVE-2023-50332: Weseek Growi

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention.

Affected products

  • Weseek Growi: before 6.0.6 (fixed in 6.0.6)

Published 2023-12-26. Last modified 2026-06-17.