Cross Site Request Forgery Vulnerability in Grocy by Grocy Team
CVE-2023-42270

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2023

What is CVE-2023-42270?

The version of Grocy up to and including 4.0.2 is susceptible to Cross Site Request Forgery, which enables an attacker to induce a victim to execute unwanted actions on a web application where they are authenticated. This vulnerability can lead to unauthorized access or manipulation of user data, raising severe security risks for applications relying on Grocy.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.