VYPR
Unrated severityNVD Advisory· Published Jan 6, 2025· Updated Jan 6, 2025

CVE-2024-55074

CVE-2024-55074

Description

The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.

Affected products

2
  • Grocy Project/Grocyllm-fuzzy2 versions
    <=4.3.0+ 1 more
    • (no CPE)range: <=4.3.0
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.