Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9478-fw83-f763

Опубликовано: 02 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

EPSS

Процентиль: 34%
0.00138
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

EPSS

Процентиль: 34%
0.00138
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-863