CVE-2020-15253
Summary
| CVE | CVE-2020-15253 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-14 19:15:00 UTC |
| Updated | 2022-10-18 20:20:00 UTC |
| Description | Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes and products. Authentication is required to exploit these issues and Grocy should not be publicly exposed. The linked reference details a proof-of-concept. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XSS and HTML injection possible at some places · Advisory · grocy/grocy · GitHub | CONFIRM | github.com | Third Party Advisory |
| grocy 2.7.1 - Persistent Cross-Site Scripting - PHP webapps Exploit | MISC | www.exploit-db.com | |
| XSS and HTML Injection on Create Shopping List & shopping list item notes (Rendered upon deleting it) · Issue #996 · grocy/grocy · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| Excape HTML (where needed, for bootbox) (references #996) · grocy/grocy@0df2590 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Excape shopping list item notes (references #996) · grocy/grocy@0624b0d · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.