First published: Wed Nov 18 2020(Updated: )
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grocy | =2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25454.
The severity level of CVE-2020-25454 is medium, with a severity value of 5.4.
The software version affected by CVE-2020-25454 is grocy 2.7.1.
The cross-site scripting (XSS) vulnerability in grocy 2.7.1 can be exploited via the add recipe module.
Yes, a fix for CVE-2020-25454 is available. Please refer to the vendor's website or official sources for the patch or update.