5.4
CVSSv3

CVE-2023-48197

Published: 15/11/2023 Updated: 24/01/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and previous versions allows malicious users to obtain victim's cookies when the victim clicks on the "see QR code" function.

Vulnerable Product Search on Vulmon Subscribe to Product

grocy project grocy 4.0.3