In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the…
mitre·CWE-639·Published 2019-07-09