Grocy Information Disclosure Vulnerability

Vulnerability

An information disclosure vulnerability exists in Grocy versions through 4.3.0. It allows remote attackers to access sensitive data by directly requesting pages that are not visible in the user interface, such as the calendar and recipes. This issue is a result of broken access control, where unauthorized users can bypass restrictions by accessing certain URLs or API endpoints directly.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as recipe details and calendar entries.

Reproduction

To reproduce this vulnerability, create a user with no permissions and log in. Then, directly access the calendar or recipe URLs, which will return data despite the lack of authorization for those functions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
9.5
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.