Cross-site scripting vulnerability in Grocy up to 4.2.0
CVE-2024-8370
What is CVE-2024-8370?
A serious security flaw has been identified in Grocy, specifically affecting versions up to 4.2.0, related to the SVG File Upload Handler. The vulnerability arises from improper handling of the 'force_serve_as' argument within the /api/files/recipepictures/ endpoint. This issue enables potential attackers to execute a cross-site scripting (XSS) attack remotely by manipulating inputs intended for picture uploads. While the existence and impact of this vulnerability have been publicly disclosed, the project maintainer has refrained from providing an official statement on the situation. According to the project's security policy, concerns regarding this vulnerability are deemed 'practically irrelevant' due to the necessity for authentication to exploit the issue, but it is crucial for users to evaluate their security posture regarding this risk.
Affected Version(s)
Grocy 4.0.0
Grocy 4.0.1
Grocy 4.0.2
