Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the users intention.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Growi | Weseek | * | 6.0.6 (excluding) |