CVE-2024-55075

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
06/01/2025
Last modified:
29/09/2025

Description

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grocy_project:grocy:*:*:*:*:*:*:*:* 4.3.0 (including)