CVE-2024-55070

Published
View on NVD ↗
CVSS v3
3.1
LOW
CVSS v2
N/A
Affected
1
PROJECT

Description

A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allows group managers to edit their own permissions.

Mealie is a self hosted recipe manager and meal planner with a RestAPI backend and a reactive frontend application built in Vue for a pleasant user experience for the whole family. Easily add recipes into your database by providing the url and mealie will automatically import the relevant data or add a family recipe with the UI editor
GitHubGitHub
12.4K