Cross-Site Scripting Vulnerability in Grocy Product Description Component
CVE-2023-48198
5.4MEDIUM
Key Information:
- Vendor
Grocy Project
- Status
- Vendor
- CVE Published:
- 15 November 2023
Badges
๐พ Exploit Exists
What is CVE-2023-48198?
A Cross-Site Scripting vulnerability exists in the 'product description' component of the Grocy application, specifically within the '/api/stock/products' endpoint, affecting versions 4.0.3 and earlier. This security flaw allows attackers to manipulate the content and potentially retrieve sensitive information, such as user cookies, from victims accessing the compromised feature.
