Описание
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
Ссылки
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:mealie:mealie:0.5.5:*:*:*:*:*:*:*
cpe:2.3:a:mealie:mealie:1.0.0:beta3:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00368
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
EPSS
Процентиль: 58%
0.00368
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-639