Loading HuntDB...

GHSA-5q4h-2vw3-5vc3

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settings may be changed without the user's intention.

Related CVEs

Key Information

GHSA ID
GHSA-5q4h-2vw3-5vc3
Published
December 26, 2023 9:30 AM
Last Modified
January 4, 2024 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 16, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.