Impact
Authenticated users can craft requests to the ratings and favorites endpoints with arbitrary user identifiers, bypassing the ownership check. This allows the disclosure of private recipe identifiers, rating values, and favorite flags for users in other groups or households, thereby violating user privacy and potentially exposing sensitive content.
Affected Systems
The vulnerability affects all installations of Mealie from versions prior to 3.21.0. The affected product is Mealie, a recipe management application maintained by mealie-recipes. Any instance running a vulnerable version and accessible to authenticated users is impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of 0.0028 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires only valid authentication and does not require elevated privileges, making it relatively straightforward for an attacker with access to any user account to pull data about other users.
OpenCVE Enrichment