Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| weseek / growi | 4.2.0 | 4.2.7.x |