#VU66675 Information disclosure in Mealie - CVE-2022-34623
Published: August 22, 2022
Vulnerability identifier: #VU66675
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-34623
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Mealie
Mealie
Software vendor:
hay-kot
hay-kot
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a flaw in the authentication process. A remote attacker can send a specially crafted request using improper username and password and gain unauthorized access to sensitive information on the system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.