CVE-2017-16946
25.11.2017, 18:29
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.Enginsight
Vendor | Product | Version |
---|---|---|
misp | misp | 2.4.82 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration