CVE-2025-61994

Publication date

2025-11-06 04:14:30

Family

jpcert

State

PUBLISHED

Description

Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.