Stored XSS in Grocy
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes and products. Authentication is required to exploit these issues and Grocy should not be publicly exposed. The linked reference details a proof-of-concept.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Affected products
grocy · grocyReferences
https://github.com/grocy/grocy/commit/0624b0df594a4353ef25e6b1874565ea52ce7772https://github.com/grocy/grocy/commit/0df2590de27c60c18b7db6e056347bd2aff5a887https://github.com/grocy/grocy/issues/996https://github.com/grocy/grocy/security/advisories/GHSA-7f37-2fjr-v9p7https://www.exploit-db.com/exploits/48792