Cross-site Scripting Vulnerability in Grocy Household Management Solution
CVE-2020-25454
5.4MEDIUM
What is CVE-2020-25454?
A Cross-site Scripting (XSS) vulnerability exists in Grocy 2.7.1, specifically within the add recipe module. The flaw can be exploited when a user deletes a recipe, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser. This vulnerability poses a significant risk to user data and may lead to unauthorized actions within the application. It is imperative for users to update their installations to mitigate potential exploitation.
