logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-15253

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-15253

Description:
Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes and products. Authentication is required to exploit these issues and Grocy should not be publicly exposed. The linked reference details a proof-of-concept.
Last updated date:
10/18/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/16/2020
Reference url to background

https://github.com/grocy/grocy/issues/996

Type:
exploit
Confidence:
HIGH
Date of publishing:
10/18/2022
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy