Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m62g-7v8j-3fwc

Опубликовано: 16 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

EPSS

Процентиль: 38%
0.0044
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.9
nvd
около 2 лет назад

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

CVSS3: 4.9
debian
около 2 лет назад

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 ...

EPSS

Процентиль: 38%
0.0044
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863