Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unknown
Any version
affected
Description
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Problem types
CWE-425 Direct Request ('Forced Browsing')
Product status
Any version
References
m10x.de/...d-broken-access-control-vulnerabilities-in-grocy/