In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic authentication is required.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-09T19:28:37

Updated: 2019-07-09T19:28:37

Reserved: 2019-07-05T00:00:00


Link: CVE-2019-13337

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-07-09T20:15:10.713

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-13337

JSON object: View

cve-icon Redhat Information

No data.