PoC Index

CVE-2024-55075

MEDIUM 5.3EPSS 0.5%

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.52% chance of exploitation in the next 30 days, 42th percentile
Published
2025-01-06

Proof-of-concept exploits (1)

References

Related