Access Control Flaw in Grocy by M10X
CVE-2024-55075

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 January 2025

What is CVE-2024-55075?

The Grocy application version 4.3.0 is susceptible to an access control vulnerability that allows remote attackers to exploit direct requests to specific pages that are not visible within the user interface. This flaw can lead to unauthorized access to sensitive information, including calendar data and recipes, thereby compromising the security of user data. Proper access controls and restrictions should be enforced to prevent these unauthorized access attempts.

Affected Version(s)

Grocy 0 <= 4.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.