First published: Wed Nov 15 2023(Updated: )
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grocy | =4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-48197.
The severity of CVE-2023-48197 is medium.
Grocy v.4.0.3 is affected by CVE-2023-48197.
A local attacker can exploit CVE-2023-48197 by executing arbitrary code and obtaining sensitive information via the QR code function in the manageapikeys component of Grocy.
Currently, there is no known fix available for CVE-2023-48197. It is recommended to follow the vendor's advisory and apply any patches or updates as they become available.