PT-2025-4851 · Unknown · Tandoor Recipes

M10X

·

Published

2025-01-28

·

Updated

2025-01-28

·

CVE-2025-23212

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tandoor Recipes versions prior to 1.5.28
Description Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server.
Recommendations Tandoor Recipes versions prior to 1.5.28 should be updated to version 1.5.28 to fix the issue.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-23212
GHSA-JRGJ-35JX-2QQ7

Affected Products

Tandoor Recipes