Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52732 | The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370. |
Fri, 05 Sep 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:grocy_project:grocy:*:*:*:*:*:*:*:* |
Mon, 06 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 06 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-06T20:50:19.099Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-55074
Updated: 2025-01-06T20:49:24.332Z
Status : Analyzed
Published: 2025-01-06T20:15:39.060
Modified: 2025-09-05T00:23:07.703
Link: CVE-2024-55074
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:58Z
EUVD