PT-2020-14317 · Grocy · Grocy

Muffyhub

·

Published

2020-02-05

·

Updated

2022-10-18

·

CVE-2020-15253

CVSS v3.1

7.3

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grocy versions <= 2.7.1
Description The issue is related to Cross-Site Scripting that can be exploited via the Create Shopping List module when it is deleted. This problem is also present in other modules, including users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes, and products. To exploit this issue, authentication is required, and it is recommended that Grocy not be publicly exposed.
Recommendations For Grocy versions <= 2.7.1, update to a version higher than 2.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the Create Shopping List module and other affected modules until a patch is available. Additionally, ensure that Grocy is not publicly exposed to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2020-01158
CVE-2020-15253
GHSA-7F37-2FJR-V9P7

Affected Products

Grocy