Cross-Site Scripting Vulnerability in Grocy Recipe and Shopping List Components
CVE-2023-48866
5.4MEDIUM
Key Information:
- Vendor
Grocy Project
- Status
- Vendor
- CVE Published:
- 4 December 2023
Badges
๐พ Exploit Exists
What is CVE-2023-48866?
A Cross-Site Scripting (XSS) vulnerability exists in the recipe preparation component and note component of Grocy, affecting versions up to 4.0.3. This flaw can be exploited by attackers to inject malicious scripts into the application. When users interact with these compromised components, their cookies may be sent to unauthorized parties, potentially compromising user accounts and sensitive information.
