Record summary

CVE-2020-15253 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit.

Description

Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes and products. Authentication is required to exploit these issues and Grocy should not be publicly exposed. The linked reference details a proof-of-concept.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List<= 2.7.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBgrocy 2.7.1 - Persistent Cross-Site ScriptingExploitDB exploitby Mufaddal MasalawalaNot analyzed1 file
ExploitDB

PoC details

References

5