CVE-2024-55075
MEDIUMCVSS 5.3/10EPSS 0.50%
Last modified
CVE-2024-55075 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Grocy Project | Grocy | <= 4.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55075?
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
How severe is CVE-2024-55075?
CVE-2024-55075 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.50% probability of exploitation in the next 30 days.
How do I fix CVE-2024-55075?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55069ffmpeg 7.1 is vulnerable to Null Pointer Dereference in func…5.3
- CVE-2024-5507Luxion KeyShot Viewer KSP File Parsing Stack-based Buffer Ov…7.8
- CVE-2024-55070A Broken Object Level Authorization vulnerability in the com…3.1
- CVE-2024-55072A Broken Object Level Authorization vulnerability in the com…5.4
- CVE-2024-55073A Broken Object Level Authorization vulnerability in the com…7.6
- CVE-2024-55074The edit profile function of Grocy through 4.3.0 allows stor…9
- CVE-2024-55076Grocy through 4.3.0 has no CSRF protection, as demonstrated …8.1
- CVE-2024-55078An arbitrary file upload vulnerability in the component /adm…9.8
- CVE-2024-5508Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write R…7.8
- CVE-2024-55081An XML External Entity (XXE) injection vulnerability in the …9.8
- CVE-2024-55082A Server-Side Request Forgery (SSRF) in the endpoint http://…7.5
- CVE-2024-55085GetSimple CMS CE 3.3.19 suffers from arbitrary code executio…9.8
Are you affected by CVE-2024-55075?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
