
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15253 is a Stored Cross-Site Scripting (XSS) vulnerability affecting grocy household management solution version 2.7.1 and earlier. The vulnerability was discovered in the Create Shopping List module, where malicious code could be injected and rendered when deleting a shopping list. The issue was disclosed on September 6, 2020 and patched in versions after 2.7.1 (GitHub Advisory).
The vulnerability allows an attacker to inject arbitrary HTML and JavaScript code via the shopping list name field, which gets executed when the shopping list is deleted. The injection point is in the Create Shopping List module's name input field, with the payload being rendered upon deletion of that shopping list. The vulnerability was rated as Low severity by the vendor (GitHub Advisory).
The vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of other users' browsers, potentially leading to session cookie theft and account compromise. However, the vendor noted this as 'uncritical and practically irrelevant' given the application's intended use case (GitHub Advisory).
A proof-of-concept exploit exists demonstrating how an authenticated user can inject malicious code through the shopping list name field. The vulnerability requires authentication to exploit (Exploit DB).
The vulnerability was patched in versions after 2.7.1 by implementing proper HTML escaping for user input. Users should upgrade to a version newer than 2.7.1 to receive the fix (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."