CVE-2019-13338

Publication date

2019-07-09 19:27:57

Family

mitre

State

PUBLISHED

Description

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.