CVE-2024-55075

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 6, 2025
CWE ID 425

Summary

CVE-2024-55075 is a newly disclosed vulnerability in Grocy, an open-source inventory management application, up to version 4.3.0. This issue permits remote attackers to access sensitive information, including calendar and recipe data, that is not visible through the user interface. An attacker can make direct requests to these hidden pages, bypassing intended access controls and potentially gaining unauthorized insights. The precise method of exploitation is not detailed in the available information, but the vulnerability poses a significant risk to users and requires immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share