« Volver al listado

Grocy Project

Grocy Project Grocy: vulnerabilidades y CVE

Grocy Project Grocy tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-55076Alta (8.1)0.31%—6 ene 2025
Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
CVE-2024-55075Media (5.3)0.52%—6 ene 2025
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
CVE-2024-55074Crítica (9)0.65%—6 ene 2025
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
CVE-2024-8370Media (5.3)0.43%—1 sept 2024
A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File Upload Handler. The manipulation of the…
CVE-2023-48866Media (5.4)0.69%—4 dic 2023
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's…
CVE-2023-48200Media (5.4)0.77%—15 nov 2023
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.
CVE-2023-48199Alta (7.8)0.50%—15 nov 2023
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately…
CVE-2023-48198Media (5.4)0.67%—15 nov 2023
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies.
CVE-2023-48197Media (5.4)0.66%—15 nov 2023
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.
CVE-2023-42270Alta (8.8)0.44%—15 sept 2023
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2020-25454Media (5.4)0.74%—18 nov 2020
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript1
  2. T1078.001 Default Accounts1
  3. T1189 Drive-by Compromise1
  4. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.