Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2022-34624
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
0
Attacker Value
Unknown
CVE-2022-34621
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
0
Attacker Value
Unknown
CVE-2022-34615
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
0
Attacker Value
Unknown
CVE-2022-34625
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.
0
Attacker Value
Unknown
CVE-2022-34618
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.
0
Attacker Value
Unknown
CVE-2022-34613
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown
CVE-2022-32425
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.
0