Skip to content

XSS and HTML injection possible at some places

Low
berrnd published GHSA-7f37-2fjr-v9p7 Oct 14, 2020

Package

No package listed

Affected versions

<= 2.7.1

Patched versions

> 2.7.1

Description

Impact

This is uncritical and practically irrelevant according to the target use case of Grocy (see this project's security policy) - published only for the sake of providing a "CVE trophy".

Solution

This has been resolved on 2020-10-14, so included in all releases after v2.7.1.

More information

See #996 for more information.

Severity

Low

CVE ID

CVE-2020-15253

Weaknesses

No CWEs

Credits