Vulnerability Name: Stored Cross Site Scripting & HTML Injection Vulnerable Version: grocy household management solution v2.7.1 Vulnerable URL: http://127.0.0.1/shoppinglist/new Payloads: 1. 2. Steps to Reproduce: - Login to the application - Go to 'Shopping List' module - Click on 'New Shopping List' module - Enter the payload in 'Name' input field - Click Save - Click 'Delete Shopping List' Description: - Allows stored XSS and HTML Injection via the 'New Shopping List' module, rendered upon deleting the Shopping List. - XSS can lead to cookie theft, session hijacking, and page content modification. - HTML Injection can lead to arbitrary HTML injection into a vulnerable web page. Milestone: v3.0.0 Status: Closed on Dec 22, 2020