CVE-2024-55073

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Mar 27, 2025
Updated: Apr 11, 2025
CWE ID 862

Summary

CVE-2024-55073 is a newly identified Object Level Authorization (OLA) vulnerability affecting the component /api/users/{user-id} in the hay-kot mealie v2.2.0. This issue enables users to edit their own profiles, granting them the ability to increase their permissions or modify their household settings, potentially leading to unintended and unauthorized access or modifications within the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share