CVE-2024-55075
CVE-2024-55075
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.5%KEV nãoPoC —Patch —
Lifecycle
06 Jan 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Grocy project · GrocyWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →