Security Advisory

CVE-2025-61994

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-06 04:14:30
Last updated 2025-11-06 14:09:38
Assigner jpcert
CVSS score 5.4
State PUBLISHED

Description

Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.