Tandoor Recipes - Local file disclosure - Users can read the content of any file on the server
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short
Tandoor Recipes has a flaw that lets users read any file stored on the server through its external storage feature. This exposes sensitive information like configuration files and private data that should be protected.
Technical detail
The external storage feature in Tandoor Recipes fails to properly restrict file access, allowing authenticated or unauthenticated users to enumerate and retrieve arbitrary files from the server filesystem. The vulnerability stems from insufficient access controls on file retrieval operations, enabling information disclosure of potentially sensitive server data. Fixed in version 1.5.28.
Summary generated and translated by AI from the official description.
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
TandoorRecipes · recipes