ZeroHour

CVE-2023-48197

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p50
Published
()
Modified
Description

Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.

Vendors
grocy project
Products
grocy
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.