PT-2020-14317 · Grocy · Grocy
Muffyhub
·
Published
2020-02-05
·
Updated
2022-10-18
·
CVE-2020-15253
CVSS v3.1
7.3
High
| Vector | AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Grocy versions <= 2.7.1
Description
The issue is related to Cross-Site Scripting that can be exploited via the Create Shopping List module when it is deleted. This problem is also present in other modules, including users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes, and products. To exploit this issue, authentication is required, and it is recommended that Grocy not be publicly exposed.
Recommendations
For Grocy versions <= 2.7.1, update to a version higher than 2.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the Create Shopping List module and other affected modules until a patch is available. Additionally, ensure that Grocy is not publicly exposed to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grocy