Cross-site scripting vulnerability in Grocy up to 4.2.0
CVE-2024-8370

3.5LOW

Key Information:

Vendor

Grocy

Status
Vendor
CVE Published:
1 September 2024

What is CVE-2024-8370?

A serious security flaw has been identified in Grocy, specifically affecting versions up to 4.2.0, related to the SVG File Upload Handler. The vulnerability arises from improper handling of the 'force_serve_as' argument within the /api/files/recipepictures/ endpoint. This issue enables potential attackers to execute a cross-site scripting (XSS) attack remotely by manipulating inputs intended for picture uploads. While the existence and impact of this vulnerability have been publicly disclosed, the project maintainer has refrained from providing an official statement on the situation. According to the project's security policy, concerns regarding this vulnerability are deemed 'practically irrelevant' due to the necessity for authentication to exploit the issue, but it is crucial for users to evaluate their security posture regarding this risk.

Affected Version(s)

Grocy 4.0.0

Grocy 4.0.1

Grocy 4.0.2

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stux (VulDB User)
.