Vulnerabilities > CVE-2022-34621 - Authorization Bypass Through User-Controlled Key vulnerability in Mealie 0.5.5/1.0.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
mealie
CWE-639

Summary

Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.

Vulnerable Configurations

Part Description Count
Application
Mealie
2