CVE-2024-55074

The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
Configurations

Configuration 1 (hide)

cpe:2.3:a:grocy_project:grocy:*:*:*:*:*:*:*:*

History

05 Sep 2025, 00:23

Type Values Removed Values Added
First Time Grocy Project grocy
Grocy Project
References () https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy/ - () https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:grocy_project:grocy:*:*:*:*:*:*:*:*
Summary
  • (es) La función de edición de perfil de Grocy hasta la versión 4.3.0 permite el XSS almacenado y la escalada de privilegios resultante mediante la carga de un archivo HTML o SVG manipulado específicamente, un problema diferente a CVE-2024-8370.

06 Jan 2025, 21:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy/ - () https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy/ -

06 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 20:15

Updated : 2025-09-05 00:23


NVD link : CVE-2024-55074

Mitre link : CVE-2024-55074

CVE.ORG link : CVE-2024-55074


JSON object : View

Products Affected

grocy_project

  • grocy
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')