Описание
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-34621
- https://cwe.mitre.org/data/definitions/639.html
- https://docs.mealie.io/changelog/v0.5.6
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624
- https://hub.docker.com/r/hkotel/mealie
- https://portswigger.net/web-security/access-control/idor
Связанные уязвимости
CVSS3: 6.5
nvd
больше 3 лет назад
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.