High
CVSS 8.8
Overview
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant...
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
This vulnerability is rated 🟠 HIGH.
Recommended actions: