Stored XSS Vulnerability in Grocy Allows Privilege Escalation
CVE-2024-55074
8.8HIGH
What is CVE-2024-55074?
A security issue exists in Grocy, allowing malicious actors to exploit the edit profile function in versions up to 4.3.0. This vulnerability permits the upload of specially crafted HTML or SVG files, leading to stored Cross-Site Scripting (XSS) attacks. Such attacks can result in privilege escalation, potentially giving unauthorized users elevated access rights within the application. Users are advised to monitor their versions and implement necessary security updates to mitigate these risks.
Affected Version(s)
Grocy 0 <= 4.3.0
