CVE-2023-48199

HIGH

Grocy <= 4.0.3 - HTML Injection in manageApiKeys Component

Title source: llm
STIX 2.1

Description

HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.

Scores

CVSS v3 7.8
EPSS 0.0050
EPSS Percentile 39.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
grocy_project/grocy 4.0.3
Published Nov 15, 2023
Tracked Since Feb 18, 2026