Описание
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Уязвимые конфигурации
Конфигурация 1Версия до 4.3.0 (включая)
cpe:2.3:a:grocy_project:grocy:*:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.00036
Низкий
4.3 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-425
Связанные уязвимости
CVSS3: 4.3
github
около 1 года назад
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
EPSS
Процентиль: 10%
0.00036
Низкий
4.3 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-425