CVE-2022-34621

MEDIUM

Mealie - IDOR

Title source: rule
STIX 2.1

Description

Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.

References (5)

Core 5
Core References
Third Party Advisory x_refsource_misc
https://portswigger.net/web-security/access-control/idor
Third Party Advisory x_refsource_misc
https://cwe.mitre.org/data/definitions/639.html
Product, Third Party Advisory x_refsource_misc
https://hub.docker.com/r/hkotel/mealie
Release Notes, Third Party Advisory x_refsource_misc
https://docs.mealie.io/changelog/v0.5.6/

Scores

CVSS v3 6.5
EPSS 0.0039
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-639
Status published
Products (2)
mealie/mealie 0.5.5
mealie/mealie 1.0.0 beta3
Published Aug 19, 2022
Tracked Since Feb 18, 2026