Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-34624
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
0
Attacker Value
Unknown
CVE-2022-34621
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
0
Attacker Value
Unknown
CVE-2022-34615
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
0
Attacker Value
Unknown
CVE-2022-34619
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.
0