Grocy
cpe:2.3:a:grocy_project:grocy:*:*:*:*:*:*:*
- <= 4.3.0
An information disclosure vulnerability exists in Grocy versions through 4.3.0. It allows remote attackers to access sensitive data by directly requesting pages that are not visible in the user interface, such as the calendar and recipes. This issue is a result of broken access control, where unauthorized users can bypass restrictions by accessing certain URLs or API endpoints directly.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as recipe details and calendar entries.
To reproduce this vulnerability, create a user with no permissions and log in. Then, directly access the calendar or recipe URLs, which will return data despite the lack of authorization for those functions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.