在 3.21.0 之前的 Mealie 版本中,评分和收藏接口未能正确验证用户所有权,导致经过身份验证的攻击者可以通过在 URL 路径中指定任意用户 ID,读取其他用户的食谱评分和收藏信息。攻击者可借此获取不同组或家庭下其他用户的私有食谱标识符、评分值以及收藏标记。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mealie-recipes | mealie | < 3.21.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mealie-recipes | mealie | 0 ~ 3.21.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet