CVE-2020-15253
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15253 is a Stored Cross-Site Scripting (XSS) vulnerability affecting grocy household management solution version 2.7.1 and earlier. The vulnerability was discovered in the Create Shopping List module, where malicious code could be injected and rendered when deleting a shopping list. The issue was disclosed on September 6, 2020 and patched in versions after 2.7.1 (GitHub Advisory).

Technical details

The vulnerability allows an attacker to inject arbitrary HTML and JavaScript code via the shopping list name field, which gets executed when the shopping list is deleted. The injection point is in the Create Shopping List module's name input field, with the payload being rendered upon deletion of that shopping list. The vulnerability was rated as Low severity by the vendor (GitHub Advisory).

Impact

The vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of other users' browsers, potentially leading to session cookie theft and account compromise. However, the vendor noted this as 'uncritical and practically irrelevant' given the application's intended use case (GitHub Advisory).

Exploitability

A proof-of-concept exploit exists demonstrating how an authenticated user can inject malicious code through the shopping list name field. The vulnerability requires authentication to exploit (Exploit DB).

Mitigation and workarounds

The vulnerability was patched in versions after 2.7.1 by implementing proper HTML escaping for user input. Users should upgrade to a version newer than 2.7.1 to receive the fix (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management