CVE-2024-8370 | Grocy up to 4.2.0 SVG File Upload recipepictures force_serve_as cross site scripting
A vulnerability marked as problematic has been reported in Grocy up to 4.2.0. This affects an unknown function of the file /api/files/recipepictures/ of the component SVG File Upload Handler. Performing manipulation of the argument force_serve_as with the input picture' results in cross site scripting.
This vulnerability was named CVE-2024-8370. The attack may be initiated remotely. In addition, an exploit is available.
There are still doubts about whether this vulnerability truly exists.
Unfortunately, the project maintainer does not want to be quoted in any way regarding the dispute rationale. The security policy of the project implies that this finding is "practically irrelevant" due to authentication requirements.